PT-2026-32180 · Libexif · Libexif

Kerwin

·

Published

2026-04-12

·

Updated

2026-05-26

·

CVE-2026-40385

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions libexif versions through 0.6.25
Description A flaw exists in libexif that involves an unsigned 32bit integer overflow when handling Nikon MakerNote data. This issue can lead to crashes or information leaks. The issue is limited to 32bit systems.
Recommendations Update to a version of libexif newer than 0.6.25.

Fix

Integer Overflow

Weakness Enumeration

Related Identifiers

ALSA-2026:20929
CVE-2026-40385
JLSEC-2026-151
OESA-2026-1987
OPENSUSE-SU-2026:10717-1

Affected Products

Libexif