Bug 2459354 (CVE-2026-40335) - CVE-2026-40335 libgphoto2: libgphoto2: Information disclosure via out-of-bounds read in ptp_unpack_DPV()
Summary: CVE-2026-40335 libgphoto2: libgphoto2: Information disclosure via out-of-boun...
Keywords:
Status: NEW
Alias: CVE-2026-40335
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-04-18 00:01 UTC by OSIDB Bzimport
Modified: 2026-04-20 11:19 UTC (History)
0 users

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-04-18 00:01:14 UTC
libgphoto2 is a camera access and control library. Versions up to and including 2.5.33 have an out-of-bounds read in `ptp_unpack_DPV()` in `camlibs/ptp2/ptp-pack.c` (lines 622–629). The UINT128 and INT128 cases advance `*offset += 16` without verifying that 16 bytes remain in the buffer. The entry check at line 609 only guarantees `*offset < total` (at least 1 byte available), leaving up to 15 bytes unvalidated. Commit 433bde9888d70aa726e32744cd751d7dbe94379a patches the issue.


Note You need to log in before you can comment on or make changes to this bug.