{"id":"CVE-2026-40338","summary":"libgphoto2 has OOB read in ptp_unpack_Sony_DPD() enumeration count parsing in ptp-pack.c","details":"libgphoto2 is a camera access and control library. Versions up to and including 2.5.33 have an out-of-bounds read in the PTP_DPFF_Enumeration case of `ptp_unpack_Sony_DPD()` in `camlibs/ptp2/ptp-pack.c` (line 856). The function reads a 2-byte enumeration count N via `dtoh16o(data, *poffset)` without verifying that 2 bytes remain in the buffer. The standard `ptp_unpack_DPD()` at line 704 has this exact check, confirming the Sony variant omitted it by oversight. Commit 3b9f9696be76ae51dca983d9dd8ce586a2561845 fixes the issue.","aliases":["GHSA-2hwp-w84q-27hf"],"modified":"2026-08-12T16:25:08.157947Z","published":"2026-04-17T23:40:10.097Z","related":["openSUSE-SU-2026:10916-1"],"database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-125"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/40xxx/CVE-2026-40338.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/40xxx/CVE-2026-40338.json"},{"type":"ADVISORY","url":"https://github.com/gphoto/libgphoto2/security/advisories/GHSA-2hwp-w84q-27hf"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-40338"},{"type":"FIX","url":"https://github.com/gphoto/libgphoto2/commit/3b9f9696be76ae51dca983d9dd8ce586a2561845"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/gphoto/libgphoto2","events":[{"introduced":"0"},{"fixed":"3b9f9696be76ae51dca983d9dd8ce586a2561845"}],"database_specific":{"source":["AFFECTED_FIELD","REFERENCES"],"extracted_events":[{"introduced":"0"},{"last_affected":"2.5.33"}]}}],"versions":["v2.5.32","libgphoto2-2_5_32-release","v2.5.31","libgphoto2-2_5_31-release","v2.5.30","libgphoto2-2_5_30-release","v2.5.29","libgphoto2-2_5_29-release","v2.5.28","libgphoto2-2_5_28-release","v2.5.27","libgphoto2-2_5_27-release","v2.5.26","libgphoto2-2_5_26-release","v2.5.25","libgphoto2-2_5_25-release","v2.5.24","libgphoto2-2_5_24-release","libgphoto2-2_5_23-release","libgphoto2-2_5_22-release","libgphoto2-2_5_21-release","libgphoto2-2_5_20-release","libgphoto2-2_5_19-release","libgphoto2-2_5_18-release","libgphoto2-2_5_17-release","libgphoto2-2_5_16-release","libgphoto2-2_5_15-release","libgphoto2-2_5_14-release","libgphoto2-2_5_13-release","libgphoto2-2_5_12-release","libgphoto2-2_5_11-release","libgphoto2-2_5_10-release","libgphoto2-2_5_9-release","libgphoto2-2_5_8-release","libgphoto2-2_5_7-release","libgphoto2-2_5_6-release","libgphoto2-2_5_5_1-release","libgphoto2-2_5_5-release","libgphoto2-2_5_4-release","libgphoto2-2_5_3_1-release","libgphoto2-2_5_3-release","libgphoto2-2_5_2-release","libgphoto2-2_5_1_1-release","libgphoto2-2_5_1-release","libgphoto2-2_5_0-release"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-40338.json","vanir_signatures_modified":"2026-08-12T16:25:08Z","vanir_signatures":[{"deprecated":false,"digest":{"function_hash":"21965023955985201892548801764292135121","length":4187},"id":"CVE-2026-40338-595dd851","signature_type":"Function","signature_version":"v1","source":"https://github.com/gphoto/libgphoto2/commit/3b9f9696be76ae51dca983d9dd8ce586a2561845","target":{"function":"ptp_unpack_Sony_DPD","file":"camlibs/ptp2/ptp-pack.c"}},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/gphoto/libgphoto2/commit/3b9f9696be76ae51dca983d9dd8ce586a2561845","target":{"file":"camlibs/ptp2/ptp-pack.c"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["236872050466299106511125346444051247505","176932953261585094079536782933750801386","126427036254075555145455405924006108582"]},"id":"CVE-2026-40338-fa21efd2"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L"}]}