PT-2026-33539 · Gphotos · Libgphoto2
Published
2026-04-17
·
Updated
2026-04-18
·
CVE-2026-40341
CVSS v3.1
3.5
Low
| AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L |
libgphoto2 is a camera access and control library. In versions up to and including 2.5.33, an out of bound read in ptp unpack EOS FocusInfoEx could be used to crash libgphoto2 when processing input from untrusted USB devices. Commit c385b34af260595dfbb5f9329526be5158985987 contains a patch. No known workarounds are available.
Fix
Buffer Over-read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Libgphoto2