← Vulnerability feed

Vulnerability record · CVE-2026-40385 · published 12 April 2026

CVE-2026-40385: Libexif project libexif integer overflow vulnerability

LLibexif Project · Libexif

In libexif through 0.6.25, an unsigned 32bit integer overflow in Nikon MakerNote handling could be used by local attackers to cause crashes or information leaks. This only affects 32bit systems.

7.1 CVSS 3.1 High EPSS 0.13% · top 98.1% CWE-190 · Integer overflow
7.1CVSS 3.1 base score
0.13%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

In libexif through 0.6.25, an unsigned 32bit integer overflow in Nikon MakerNote handling could be used by local attackers to cause crashes or information leaks. This only affects 32bit systems.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-40385 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.1CVE-2020-13112Libexif project libexif out-of-bounds read vulnerabilityAn issue was discovered in libexif before 0.6.22. Several buffer over-reads in EXIF MakerNote handling could lead to information disclosure and crash…EPSS 2.7%9.1CVE-2017-7544Libexif project libexif out-of-bounds read vulnerabilitylibexif through 0.6.21 is vulnerable to out-of-bounds heap read vulnerability in exif_data_save_data_entry function in libexif/exif-data.c caused by …EPSS 3.3%8.2CVE-2020-13113Libexif project libexif use of uninitialized resource vulnerabilityAn issue was discovered in libexif before 0.6.22. Use of uninitialized memory in EXIF Makernote handling could lead to crashes and potential use-afte…EPSS 1.9%8.1CVE-2016-6328Libexif project libexif integer overflow vulnerabilityA vulnerability was found in libexif. An integer overflow when parsing the MNOTE entry data of the input file. This can cause Denial-of-Service (DoS)…EPSS 1.7%7.8CVE-2026-32775Libexif project libexif vulnerabilitylibexif through 0.6.25 has a flaw in decoding MakerNotes. If the exif_mnote_data_get_value function gets passed in a 0 size, the passed in-buffer wou…EPSS 0.16%7.5CVE-2020-0198Google android integer overflow vulnerabilityIn exif_data_load_data_content of exif-data.c, there is a possible UBSAN abort due to an integer overflow. This could lead to remote denial of servic…EPSS 4.3%7.5CVE-2020-0181Google android integer overflow vulnerabilityIn exif_data_load_data_thumbnail of exif-data.c, there is a possible denial of service due to an integer overflow. This could lead to remote denial o…EPSS 2.9%7.5CVE-2020-13114Libexif project libexif allocation without limits vulnerabilityAn issue was discovered in libexif before 0.6.22. An unrestricted size in handling Canon EXIF MakerNote data could lead to consumption of large amoun…EPSS 2.3%

Source: NIST National Vulnerability Database (record CVE-2026-40385), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.