libgphoto2 is a camera access and control library. In versions up to and including 2.5.33, an out of bound read in ptpunpackEOS_FocusInfoEx could be used to crash libgphoto2 when processing input from untrusted USB devices. Commit c385b34af260595dfbb5f9329526be5158985987 contains a patch. No known workarounds are available.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/40xxx/CVE-2026-40341.json",
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-126"
]
}"2026-07-15T19:00:06Z"
[
{
"digest": {
"line_hashes": [
"258582655906751970630966496938119664281",
"78941112976921275711734457015865885946",
"109452470182342557781666884678836204697",
"137015440017492297459704849380306134567",
"11872365305191241721873721091898219903",
"217711385345284542476141326597538388102",
"51405930467384719432128832685877843624",
"103606243712705923082730633945678828229",
"29271901911609501005610000736690207846",
"287042753991492628820909275322865098100",
"297612241182069321913886235904793627351",
"11285748948342657144024348675136217658",
"320013745673967842719584336044105969473",
"245868370601042827262422469940129334302",
"45121726755038169435815110667949712633",
"7089693294881952297198767655197687162",
"141731332143824515363864819925460499351",
"145433640442775531218402450246076574952",
"332157298026318059049292425920315687697"
],
"threshold": 0.9
},
"deprecated": false,
"signature_type": "Line",
"id": "CVE-2026-40341-5614777c",
"signature_version": "v1",
"source": "https://github.com/gphoto/libgphoto2/commit/c385b34af260595dfbb5f9329526be5158985987",
"target": {
"file": "camlibs/ptp2/ptp-pack.c"
}
},
{
"digest": {
"function_hash": "80995179379386253128631383211137099139",
"length": 2498.0
},
"deprecated": false,
"signature_type": "Function",
"id": "CVE-2026-40341-901db5c8",
"signature_version": "v1",
"source": "https://github.com/gphoto/libgphoto2/commit/c385b34af260595dfbb5f9329526be5158985987",
"target": {
"file": "camlibs/ptp2/ptp-pack.c",
"function": "ptp_unpack_EOS_FocusInfoEx"
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-40341.json"