libgphoto2 is a camera access and control library. In versions up to and including 2.5.33, two functions in camlibs/ptp2/ptp-pack.c accept a data pointer but no length parameter, performing unbounded reads. Their callers in ptpunpackEOS_events() have xsize available but never pass it, leaving both functions unable to validate reads against the actual buffer boundary. Commit 1817ecead20c2aafa7549dac9619fe38f47b2f53 patches the issue.
{
"cwe_ids": [
"CWE-125"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/40xxx/CVE-2026-40333.json",
"cna_assigner": "GitHub_M"
}"2026-07-15T15:20:04Z"
[
{
"signature_type": "Function",
"target": {
"file": "camlibs/ptp2/ptp-pack.c",
"function": "ptp_unpack_EOS_CustomFuncEx"
},
"deprecated": false,
"source": "https://github.com/gphoto/libgphoto2/commit/1817ecead20c2aafa7549dac9619fe38f47b2f53",
"id": "CVE-2026-40333-3efd4f4a",
"signature_version": "v1",
"digest": {
"function_hash": "187773083024042894715434365104382309351",
"length": 549.0
}
},
{
"signature_type": "Function",
"target": {
"file": "camlibs/ptp2/ptp-pack.c",
"function": "ptp_unpack_EOS_events"
},
"deprecated": false,
"source": "https://github.com/gphoto/libgphoto2/commit/1817ecead20c2aafa7549dac9619fe38f47b2f53",
"id": "CVE-2026-40333-5d4df8af",
"signature_version": "v1",
"digest": {
"function_hash": "216601163091624711277640039150689172736",
"length": 27027.0
}
},
{
"signature_type": "Line",
"target": {
"file": "camlibs/ptp2/ptp-pack.c"
},
"deprecated": false,
"source": "https://github.com/gphoto/libgphoto2/commit/1817ecead20c2aafa7549dac9619fe38f47b2f53",
"id": "CVE-2026-40333-75fbe1a4",
"signature_version": "v1",
"digest": {
"line_hashes": [
"31247186823870324881941595149644406645",
"181650701610078029459347851225294922676",
"326777093829953746672162661258786183107",
"104075578307714798014506250557233986058",
"310603498504827655325641777160869563337",
"232772760061082336706605352855527061036",
"281675078043300462470885749290509255744",
"251451043249259644606491332110692422157",
"187813660548671260838906513575284388099",
"11148562663238937480500326802665231928",
"171256714957165336664885387427984056868",
"135758857363633461770725652545979360428",
"305928467372017020437652388753673932184",
"272426123438879885592762107765372751749",
"101280182372549179392601603359337585805",
"202696839018326230639898086384334250107",
"209024316975917790629201159830867989166",
"111775972529928814601319454673139650005",
"129308752314333347709755973168824391314",
"177600061633112017865579422595971638287",
"117794945153695034984849557998427003613",
"279208877703414285005711345571302226997",
"272426123438879885592762107765372751749",
"101280182372549179392601603359337585805",
"183704278037271723722006974265434609263",
"281225321260761496691674889483556361100",
"49261725344826878072247832377942833568",
"263676490927445622626203884198192422747",
"162011904028168693996350831473156101439",
"228914125835911287285183172667097525998",
"111462244053591476474461964997725139415",
"46135038111454008143682302855235049721",
"38848830999309475103918194415364261630",
"314181820601544853654446479208645553601",
"314210672344373345923846451175432170104",
"178839050248633742153926691165420313649",
"106806912143967051388369806108834708183",
"207063819849210555866299451234358007156",
"199398957491635483197857394535347793108",
"259476348821786180621888990220211415287",
"149690223067147366014771664884954807873",
"85473535792757341590157006763046966162",
"90688419177353522433832139541445715500",
"165815629785626769006851447128330548273",
"95699452920638090369496719065120944955",
"98740549746772532345911081640012754479",
"104133722587246174359975764640509934954"
],
"threshold": 0.9
}
},
{
"signature_type": "Function",
"target": {
"file": "camlibs/ptp2/ptp-pack.c",
"function": "ptp_unpack_EOS_ImageFormat"
},
"deprecated": false,
"source": "https://github.com/gphoto/libgphoto2/commit/1817ecead20c2aafa7549dac9619fe38f47b2f53",
"id": "CVE-2026-40333-764ef1a5",
"signature_version": "v1",
"digest": {
"function_hash": "170355331672495417453570745310261305217",
"length": 1162.0
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-40333.json"