PT-2026-32180 · Libexif+3 · Libexif+3

·

CVE-2026-40385

·

Published

2026-04-12

·

Updated

2026-07-13

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions libexif versions through 0.6.25
Description A flaw exists in libexif that involves an unsigned 32bit integer overflow when handling Nikon MakerNote data. This issue can lead to crashes or information leaks. The issue is limited to 32bit systems.
Recommendations Update to a version of libexif newer than 0.6.25.

Exploit

Fix

DoS

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:20929
ALSA-2026:22553
BDU:2026-10464
CVE-2026-40385
JLSEC-2026-151
OESA-2026-1987
OPENSUSE-SU-2026:10717-1
OPENSUSE-SU-2026:21023-1
RHSA-2026:20929
RHSA-2026:22553
RHSA-2026:26190
RHSA-2026:26191
RHSA-2026:26192
RHSA-2026:26224
RHSA-2026:26276
RHSA-2026:26292
RHSA-2026:26567
SUSE-SU-2026:22324-1
SUSE-SU-2026:2837-1
SUSE-SU-2026:2838-1
USN-8531-1

Affected Products

Linuxmint
Red Os
Rocky Linux
Libexif