CVE-2026-40333

Source
https://cve.org/CVERecord?id=CVE-2026-40333
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-40333.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-40333
Aliases
  • GHSA-hq94-cp6h-3gjp
Downstream
Related
Published
2026-04-17T23:11:11.073Z
Modified
2026-07-15T15:20:04.730645Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H CVSS Calculator
Summary
libgphoto2 has OOB read in ptp_unpack_EOS_ImageFormat() and ptp_unpack_EOS_CustomFuncEx() due to missing length parameter in ptp-pack.c
Details

libgphoto2 is a camera access and control library. In versions up to and including 2.5.33, two functions in camlibs/ptp2/ptp-pack.c accept a data pointer but no length parameter, performing unbounded reads. Their callers in ptpunpackEOS_events() have xsize available but never pass it, leaving both functions unable to validate reads against the actual buffer boundary. Commit 1817ecead20c2aafa7549dac9619fe38f47b2f53 patches the issue.

Database specific
{
    "cwe_ids": [
        "CWE-125"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/40xxx/CVE-2026-40333.json",
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/gphoto/libgphoto2

Affected ranges

Type
GIT
Repo
https://github.com/gphoto/libgphoto2
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.5.33"
        }
    ]
}

Affected versions

Other
libgphoto2-2_5_0-release
libgphoto2-2_5_1-release
libgphoto2-2_5_10-release
libgphoto2-2_5_11-release
libgphoto2-2_5_12-release
libgphoto2-2_5_13-release
libgphoto2-2_5_14-release
libgphoto2-2_5_15-release
libgphoto2-2_5_16-release
libgphoto2-2_5_17-release
libgphoto2-2_5_18-release
libgphoto2-2_5_19-release
libgphoto2-2_5_1_1-release
libgphoto2-2_5_2-release
libgphoto2-2_5_20-release
libgphoto2-2_5_21-release
libgphoto2-2_5_22-release
libgphoto2-2_5_23-release
libgphoto2-2_5_24-release
libgphoto2-2_5_25-release
libgphoto2-2_5_26-release
libgphoto2-2_5_27-release
libgphoto2-2_5_28-release
libgphoto2-2_5_29-release
libgphoto2-2_5_3-release
libgphoto2-2_5_30-release
libgphoto2-2_5_31-release
libgphoto2-2_5_32-release
libgphoto2-2_5_3_1-release
libgphoto2-2_5_4-release
libgphoto2-2_5_5-release
libgphoto2-2_5_5_1-release
libgphoto2-2_5_6-release
libgphoto2-2_5_7-release
libgphoto2-2_5_8-release
libgphoto2-2_5_9-release
v2.*
v2.5.24
v2.5.25
v2.5.26
v2.5.27
v2.5.28
v2.5.29
v2.5.30
v2.5.31
v2.5.32

Database specific

vanir_signatures_modified
"2026-07-15T15:20:04Z"
vanir_signatures
[
    {
        "signature_type": "Function",
        "target": {
            "file": "camlibs/ptp2/ptp-pack.c",
            "function": "ptp_unpack_EOS_CustomFuncEx"
        },
        "deprecated": false,
        "source": "https://github.com/gphoto/libgphoto2/commit/1817ecead20c2aafa7549dac9619fe38f47b2f53",
        "id": "CVE-2026-40333-3efd4f4a",
        "signature_version": "v1",
        "digest": {
            "function_hash": "187773083024042894715434365104382309351",
            "length": 549.0
        }
    },
    {
        "signature_type": "Function",
        "target": {
            "file": "camlibs/ptp2/ptp-pack.c",
            "function": "ptp_unpack_EOS_events"
        },
        "deprecated": false,
        "source": "https://github.com/gphoto/libgphoto2/commit/1817ecead20c2aafa7549dac9619fe38f47b2f53",
        "id": "CVE-2026-40333-5d4df8af",
        "signature_version": "v1",
        "digest": {
            "function_hash": "216601163091624711277640039150689172736",
            "length": 27027.0
        }
    },
    {
        "signature_type": "Line",
        "target": {
            "file": "camlibs/ptp2/ptp-pack.c"
        },
        "deprecated": false,
        "source": "https://github.com/gphoto/libgphoto2/commit/1817ecead20c2aafa7549dac9619fe38f47b2f53",
        "id": "CVE-2026-40333-75fbe1a4",
        "signature_version": "v1",
        "digest": {
            "line_hashes": [
                "31247186823870324881941595149644406645",
                "181650701610078029459347851225294922676",
                "326777093829953746672162661258786183107",
                "104075578307714798014506250557233986058",
                "310603498504827655325641777160869563337",
                "232772760061082336706605352855527061036",
                "281675078043300462470885749290509255744",
                "251451043249259644606491332110692422157",
                "187813660548671260838906513575284388099",
                "11148562663238937480500326802665231928",
                "171256714957165336664885387427984056868",
                "135758857363633461770725652545979360428",
                "305928467372017020437652388753673932184",
                "272426123438879885592762107765372751749",
                "101280182372549179392601603359337585805",
                "202696839018326230639898086384334250107",
                "209024316975917790629201159830867989166",
                "111775972529928814601319454673139650005",
                "129308752314333347709755973168824391314",
                "177600061633112017865579422595971638287",
                "117794945153695034984849557998427003613",
                "279208877703414285005711345571302226997",
                "272426123438879885592762107765372751749",
                "101280182372549179392601603359337585805",
                "183704278037271723722006974265434609263",
                "281225321260761496691674889483556361100",
                "49261725344826878072247832377942833568",
                "263676490927445622626203884198192422747",
                "162011904028168693996350831473156101439",
                "228914125835911287285183172667097525998",
                "111462244053591476474461964997725139415",
                "46135038111454008143682302855235049721",
                "38848830999309475103918194415364261630",
                "314181820601544853654446479208645553601",
                "314210672344373345923846451175432170104",
                "178839050248633742153926691165420313649",
                "106806912143967051388369806108834708183",
                "207063819849210555866299451234358007156",
                "199398957491635483197857394535347793108",
                "259476348821786180621888990220211415287",
                "149690223067147366014771664884954807873",
                "85473535792757341590157006763046966162",
                "90688419177353522433832139541445715500",
                "165815629785626769006851447128330548273",
                "95699452920638090369496719065120944955",
                "98740549746772532345911081640012754479",
                "104133722587246174359975764640509934954"
            ],
            "threshold": 0.9
        }
    },
    {
        "signature_type": "Function",
        "target": {
            "file": "camlibs/ptp2/ptp-pack.c",
            "function": "ptp_unpack_EOS_ImageFormat"
        },
        "deprecated": false,
        "source": "https://github.com/gphoto/libgphoto2/commit/1817ecead20c2aafa7549dac9619fe38f47b2f53",
        "id": "CVE-2026-40333-764ef1a5",
        "signature_version": "v1",
        "digest": {
            "function_hash": "170355331672495417453570745310261305217",
            "length": 1162.0
        }
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-40333.json"