PT-2026-33539 · Gphotos · Libgphoto2

Published

2026-04-17

·

Updated

2026-04-18

·

CVE-2026-40341

CVSS v3.1

3.5

Low

AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
libgphoto2 is a camera access and control library. In versions up to and including 2.5.33, an out of bound read in ptp unpack EOS FocusInfoEx could be used to crash libgphoto2 when processing input from untrusted USB devices. Commit c385b34af260595dfbb5f9329526be5158985987 contains a patch. No known workarounds are available.

Fix

Buffer Over-read

Weakness Enumeration

Related Identifiers

CVE-2026-40341

Affected Products

Libgphoto2