Overview
What is CVE-2026-40385?
In libexif through 0.6.25, an unsigned 32bit integer overflow in Nikon MakerNote handling could be used by local attackers to cause crashes or information leaks. This only affects 32bit systems.
Vulnerability intelligence
CVE-2026-40385 and is rated High severity with a CVSS score of 7.1. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.
In libexif through 0.6.25, an unsigned 32bit integer overflow in Nikon MakerNote handling could be used by local attackers to cause crashes or information leaks. This only affects 32bit systems.