Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-40385

28
FAUCET Score

CVE-2026-40385 is an unsigned 32-bit integer overflow vulnerability in libexif through version 0.6.25 affecting Nikon MakerNote handling, with impact limited to 32-bit systems. This vulnerability can be exploited by local attackers to trigger application crashes or leak sensitive information from memory. The vulnerability carries a CVSS score of 7.1 (HIGH) with a local attack vector requiring low complexity and user privileges but no interaction. The EPSS score of 0.0001 indicates minimal current exploit prevalence, and the vulnerability is not listed on the CISA Known Exploited Vulnerabilities catalog, suggesting no active exploitation in the wild. Community attention appears limited given the inactive status on security hotlists, though the moderate FAUCET Risk Score of 47.0 indicates organizations should still prioritize patching 32-bit systems running affected versions.

Impacted Technologies

VendorProductVersion(s)CPE
>= 0, <= 0.6.25CPE match
cpe:2.3:a:libexif_project:libexif:*:*:*:*:*:*:*:*
<= 0.6.25CPE matchmatch criteria
cpe:2.3:a:libexif_project:libexif:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

4.0MEDIUM

CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L

Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
NONE
Availability Impact
LOW
Exploitability Score
1.4
Impact Score
2.5
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.09%
Probability of exploitation in next 30 days
EPSS Percentile
0.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0009 is in the 3rd percentile among its peer group of 16,994 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (9)

microsoftpatch availablevia msrc
Product: azl3 libexif 0.6.24-2 on Azure Linux 3.0Fixed in: 0.6.24-3
microsoftpatch availablevia msrc
Product: cbl2 libexif 0.6.24-2 on CBL Mariner 2.0Fixed in: 0.6.24-3
microsoftpatch availablevia msrc
Product: azl3 libexif 0.6.24-3 on Azure Linux 3.0Fixed in: 0.6.24-3
microsoftpatch availablevia msrc
Product: 21198-17084Fixed in: 0.6.24-3
microsoftpatch availablevia msrc
Product: 21131-17086Fixed in: 0.6.24-3
microsoftpatch availablevia msrc
Product: 21283-17084Fixed in: 0.6.24-3
ubuntupatch availablevia ubuntu_usn
Product: libexif (jammy)Fixed in: 0.6.24-1ubuntu0.22.04.1
ubuntupatch availablevia ubuntu_usn
Product: libexif (noble)Fixed in: 0.6.24-1ubuntu0.24.04.1
ubuntupatch availablevia ubuntu_usn
Product: libexif (resolute)Fixed in: 0.6.25-2ubuntu0.1

Vendor Advisories (2)

ubuntuUSN-8531-1

libexif vulnerabilities

Jul 13, 2026
microsoft2026-Apr/CVE-2026-40385Moderate

In libexif through 0.6.25, an unsigned 32bit integer overflow in Nikon MakerNote handling could be used by local attackers to cause crashes or information leaks. This only affects 32bit systems.

Apr 14, 2026

References

github.com / libexif/libexif/commit/93003b93e50b3d259bd2227d8775b73a53c35d58
Patch