Unsigned Integer Overflow Vulnerability in libexif Affecting Nikon Products
CVE-2026-40385

4MEDIUM

Key Information:

Status
Vendor
CVE Published:
12 April 2026

What is CVE-2026-40385?

An unsigned 32-bit integer overflow has been identified in the Nikon MakerNote handling within libexif version 0.6.25 and earlier. This vulnerability could be exploited by local attackers on 32-bit systems, potentially leading to application crashes or unauthorized information leaks. Users and developers should apply the latest patches and review their systems for exposure to such attacks.

Affected Version(s)

libexif 0 <= 0.6.25

References

CVSS V3.1

Score:
4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.