CVE-2026-40385 PUBLISHED CVSS 4 MEDIUM

In libexif through 0.6.25, an unsigned 32bit integer overflow in Nikon MakerNote handling could be used by local attackers to cause crashes or information leaks. This only affects 32bit systems.

EPSS 0.01% · 1.9th percentile

Risk Scores

CVSS v3.1
4
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L
EPSS Score
0.01%
1.9th percentile

Affected Products

VendorProductVersions
libexif projectlibexif0
libexif_projectlibexif

Timeline

References

…and 2 more

Open in Interactive Console →