libgphoto2 is a camera access and control library. Versions up to and including 2.5.33 have an out-of-bounds read vulnerability in ptp_unpack_OI() in camlibs/ptp2/ptp-pack.c (lines 530–563). The function validates len < PTP_oi_SequenceNumber (i.e., len < 48) but subsequently accesses offsets 48–56, up to 9 bytes beyond the validated boundary, via the Samsung Galaxy 64-bit objectsize detection heuristic. Commit 7c7f515bc88c3d0c4098ac965d313518e0ccbe33 fixes the issue.
{
"cwe_ids": [
"CWE-125"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/40xxx/CVE-2026-40340.json",
"cna_assigner": "GitHub_M"
}"2026-07-22T00:15:44Z"
[
{
"signature_type": "Line",
"target": {
"file": "camlibs/ptp2/ptp-pack.c"
},
"deprecated": false,
"source": "https://github.com/gphoto/libgphoto2/commit/7c7f515bc88c3d0c4098ac965d313518e0ccbe33",
"id": "CVE-2026-40340-11564294",
"signature_version": "v1",
"digest": {
"line_hashes": [
"97408107183423504306935145355226358996",
"158814672851999812334003891132529031638",
"316081560164047716264162501372756446778",
"197622252246676739511558023529624353678"
],
"threshold": 0.9
}
},
{
"signature_type": "Function",
"target": {
"file": "camlibs/ptp2/ptp-pack.c",
"function": "ptp_unpack_OI"
},
"deprecated": false,
"source": "https://github.com/gphoto/libgphoto2/commit/7c7f515bc88c3d0c4098ac965d313518e0ccbe33",
"id": "CVE-2026-40340-662b80a9",
"signature_version": "v1",
"digest": {
"function_hash": "226435082960086135640613779106412484557",
"length": 1789.0
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-40340.json"