Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-40385

Опубликовано: 12 апр. 2026
Источник: redhat
CVSS3: 4
EPSS Низкий

Описание

A flaw was found in libexif. A local attacker on a 32-bit system could exploit an unsigned 32-bit integer overflow vulnerability in the Nikon MakerNote handling. This could lead to application crashes or the disclosure of sensitive information.

Отчет

This Moderate impact vulnerability in libexif affects 32-bit systems. A local attacker could trigger an integer overflow in the Nikon MakerNote handling, potentially leading to application crashes or information disclosure.

Меры по смягчению последствий

On 32-bit systems, avoid processing untrusted image files that contain Nikon MakerNotes. This operational control reduces the risk of exploitation by preventing vulnerable applications from parsing malicious EXIF data.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10libexifFix deferred
Red Hat Enterprise Linux 6libexifFix deferred
Red Hat Enterprise Linux 7libexifFix deferred
Red Hat Enterprise Linux 8libexifFix deferred
Red Hat Enterprise Linux 9libexifFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=2457687libexif: libexif: Information disclosure and crashes via integer overflow in Nikon MakerNote handling

EPSS

Процентиль: 2%
0.00013
Низкий

4 Medium

CVSS3

Связанные уязвимости

CVSS3: 4
ubuntu
2 дня назад

In libexif through 0.6.25, an unsigned 32bit integer overflow in Nikon MakerNote handling could be used by local attackers to cause crashes or information leaks. This only affects 32bit systems.

CVSS3: 4
nvd
3 дня назад

In libexif through 0.6.25, an unsigned 32bit integer overflow in Nikon MakerNote handling could be used by local attackers to cause crashes or information leaks. This only affects 32bit systems.

msrc
1 день назад

Описание отсутствует

CVSS3: 4
debian
3 дня назад

In libexif through 0.6.25, an unsigned 32bit integer overflow in Nikon ...

CVSS3: 4
github
3 дня назад

In libexif through 0.6.25, an unsigned 32bit integer overflow in Nikon MakerNote handling could be used by local attackers to cause crashes or information leaks. This only affects 32bit systems.

EPSS

Процентиль: 2%
0.00013
Низкий

4 Medium

CVSS3