PT-2026-33530 · Unknown · Libgphoto2

Published

2026-04-17

·

Updated

2026-04-20

·

CVE-2026-40336

CVSS v3.1

2.4

Low

VectorAV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions libgphoto2 versions prior to 2.5.34
Description A memory leak exists in the ptp unpack Sony DPD() function within camlibs/ptp2/ptp-pack.c. When processing a secondary enumeration list used in 2024+ Sony cameras, the function overwrites the dpd->FORM.Enum.SupportedValue variable with a new allocation without freeing the previous one. This results in the original array and its string values being leaked during every property descriptor parse.
Recommendations Update to version 2.5.34 or later.

Fix

Memory Leak

Weakness Enumeration

Related Identifiers

CVE-2026-40336

Affected Products

Libgphoto2