
CVE-2026-40385 In libexif through 0.6.25, an unsigned 32bit integer overflow in Nikon MakerNote handling could be used by local attackers to cause crashes or information leaks. This… https://www.cve.org/CVERecord?id=CVE-2026-40385
Post summary
The post briefly announces CVE‑2026‑40385, describing an unsigned 32‑bit integer overflow in libexif’s Nikon MakerNote handling that can lead to crashes or information leaks; no evidence of PoC, exploitation, patching, or false positives.

