PT-2026-33523 · Unknown · Libgphoto2

Published

2026-04-17

·

Updated

2026-04-20

·

CVE-2026-40333

CVSS v3.1

6.1

Medium

VectorAV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions libgphoto2 versions prior to 2.5.34
Description Two functions in camlibs/ptp2/ptp-pack.c accept a data pointer without a length parameter, leading to unbounded reads. The calling function ptp unpack EOS events() possesses the xsize variable but fails to pass it, preventing the functions from validating reads against the buffer boundary.
Recommendations Update to version 2.5.34 or later.

Fix

Out of bounds Read

Weakness Enumeration

Related Identifiers

CVE-2026-40333

Affected Products

Libgphoto2