CVE-2026-40338

Public on 2026-04-18
Modified on 2026-04-21
Description
libgphoto2 is a camera access and control library. Versions up to and including 2.5.33 have an out-of-bounds read in the PTP_DPFF_Enumeration case of `ptp_unpack_Sony_DPD()` in `camlibs/ptp2/ptp-pack.c` (line 856). The function reads a 2-byte enumeration count N via `dtoh16o(data, *poffset)` without verifying that 2 bytes remain in the buffer. The standard `ptp_unpack_DPD()` at line 704 has this exact check, confirming the Sony variant omitted it by oversight. Commit 3b9f9696be76ae51dca983d9dd8ce586a2561845 fixes the issue.
Severity
Low severity
Low
See what this means
CVSS v3 Base Score
3.5
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 2 - Core libgphoto2 Pending Fix

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 3.5 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L