{"id":"AZL-83015","summary":"CVE-2026-40341 affecting package libgphoto2 2.5.31-1","details":"libgphoto2 is a camera access and control library. In versions up to and including 2.5.33, an out of bound read in ptp_unpack_EOS_FocusInfoEx could be used to crash libgphoto2 when processing input from untrusted USB devices. Commit c385b34af260595dfbb5f9329526be5158985987 contains a patch. No known workarounds are available.","modified":"2026-09-02T05:29:58Z","published":"2026-04-18T00:16:38Z","upstream":["CVE-2026-40341"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-40341"}],"affected":[{"package":{"name":"libgphoto2","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/libgphoto2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"2.5.31-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-83015.json"}}],"schema_version":"1.9.0"}