Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-4558-1 | libexif security update |
Tue, 14 Apr 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 13 Apr 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | libexif: libexif: Information disclosure and crashes via integer overflow in Nikon MakerNote handling | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Sun, 12 Apr 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In libexif through 0.6.25, an unsigned 32bit integer overflow in Nikon MakerNote handling could be used by local attackers to cause crashes or information leaks. This only affects 32bit systems. | |
| First Time appeared |
Libexif Project
Libexif Project libexif |
|
| Weaknesses | CWE-190 | |
| CPEs | cpe:2.3:a:libexif_project:libexif:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Libexif Project
Libexif Project libexif |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-04-14T16:33:12.567Z
Reserved: 2026-04-12T18:16:29.829Z
Link: CVE-2026-40385
Updated: 2026-04-14T15:18:46.319Z
Status : Analyzed
Published: 2026-04-12T19:16:20.480
Modified: 2026-04-14T20:15:39.990
Link: CVE-2026-40385
OpenCVE Enrichment
Updated: 2026-04-13T12:54:05Z
Debian DLA