{"id":"AZL-83027","summary":"CVE-2026-40338 affecting package libgphoto2 2.5.31-1","details":"libgphoto2 is a camera access and control library. Versions up to and including 2.5.33 have an out-of-bounds read in the PTP_DPFF_Enumeration case of `ptp_unpack_Sony_DPD()` in `camlibs/ptp2/ptp-pack.c` (line 856). The function reads a 2-byte enumeration count N via `dtoh16o(data, *poffset)` without verifying that 2 bytes remain in the buffer. The standard `ptp_unpack_DPD()` at line 704 has this exact check, confirming the Sony variant omitted it by oversight. Commit 3b9f9696be76ae51dca983d9dd8ce586a2561845 fixes the issue.","modified":"2026-08-30T05:24:52Z","published":"2026-04-18T00:16:37Z","upstream":["CVE-2026-40338"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-40338"}],"affected":[{"package":{"name":"libgphoto2","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/libgphoto2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"2.5.31-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-83027.json"}}],"schema_version":"1.9.0"}