#VU125896 Buffer Over-read in libexif - CVE-2026-40385
Published: April 14, 2026
libexif
libexif.sourceforge.net
Description
The vulnerability allows a remote attacker to cause a denial of service or disclose sensitive information.
The vulnerability exists due to buffer over-read in Nikon MakerNotes processing when decoding or displaying Exif data with MakerNotes on 32-bit systems. A remote attacker can supply specially crafted Exif data to cause a denial of service or disclose sensitive information.
Only 32-bit systems are affected.