libgphoto2 is a camera access and control library. Versions up to and including 2.5.33 have an out-of-bounds read in ptp_unpack_DPV() in camlibs/ptp2/ptp-pack.c (lines 622–629). The UINT128 and INT128 cases advance *offset += 16 without verifying that 16 bytes remain in the buffer. The entry check at line 609 only guarantees *offset < total (at least 1 byte available), leaving up to 15 bytes unvalidated. Commit 433bde9888d70aa726e32744cd751d7dbe94379a patches the issue.
{
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-125"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/40xxx/CVE-2026-40335.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-40335.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"324882840222450677196625415089381250248",
"214554290909247072711972208966810555039",
"259307646116020475409553872968247124271",
"236030139251664998109817544700864862382",
"149392875529272673711848812283315690891",
"325020302439013694457308682135290749783",
"92615793532101981041996325438023907833"
],
"threshold": 0.9
},
"id": "CVE-2026-40335-1d1581f8",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/gphoto/libgphoto2/commit/433bde9888d70aa726e32744cd751d7dbe94379a",
"target": {
"file": "camlibs/ptp2/ptp-pack.c"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "145928571333303448235396909712962756324",
"length": 1528
},
"id": "CVE-2026-40335-25bdac96",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/gphoto/libgphoto2/commit/433bde9888d70aa726e32744cd751d7dbe94379a",
"target": {
"file": "camlibs/ptp2/ptp-pack.c",
"function": "ptp_unpack_DPV"
}
}
]
"2026-08-12T16:24:05Z"