{"id":"CVE-2026-40338","summary":"libgphoto2 has OOB read in ptp_unpack_Sony_DPD() enumeration count parsing in ptp-pack.c","details":"libgphoto2 is a camera access and control library. Versions up to and including 2.5.33 have an out-of-bounds read in the PTP_DPFF_Enumeration case of `ptp_unpack_Sony_DPD()` in `camlibs/ptp2/ptp-pack.c` (line 856). The function reads a 2-byte enumeration count N via `dtoh16o(data, *poffset)` without verifying that 2 bytes remain in the buffer. The standard `ptp_unpack_DPD()` at line 704 has this exact check, confirming the Sony variant omitted it by oversight. Commit 3b9f9696be76ae51dca983d9dd8ce586a2561845 fixes the issue.","aliases":["GHSA-2hwp-w84q-27hf"],"modified":"2026-08-04T11:50:53.829939338Z","published":"2026-04-17T23:40:10.097Z","related":["openSUSE-SU-2026:10916-1"],"database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-125"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/40xxx/CVE-2026-40338.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/40xxx/CVE-2026-40338.json"},{"type":"ADVISORY","url":"https://github.com/gphoto/libgphoto2/security/advisories/GHSA-2hwp-w84q-27hf"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-40338"},{"type":"FIX","url":"https://github.com/gphoto/libgphoto2/commit/3b9f9696be76ae51dca983d9dd8ce586a2561845"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/gphoto/libgphoto2","events":[{"introduced":"0"},{"last_affected":"fb8bd54bf1fbf019ea7fd262d7de98bce3a28701"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"2.5.33"}],"source":"AFFECTED_FIELD"}}],"versions":["v2.5.33","libgphoto2-2_5_33-release","v2.5.32","libgphoto2-2_5_32-release","v2.5.31","libgphoto2-2_5_31-release","v2.5.30","libgphoto2-2_5_30-release","v2.5.29","libgphoto2-2_5_29-release","v2.5.28","libgphoto2-2_5_28-release","v2.5.27","libgphoto2-2_5_27-release","v2.5.26","libgphoto2-2_5_26-release","v2.5.25","libgphoto2-2_5_25-release","v2.5.24","libgphoto2-2_5_24-release","libgphoto2-2_5_23-release","libgphoto2-2_5_22-release","libgphoto2-2_5_21-release","libgphoto2-2_5_20-release","libgphoto2-2_5_19-release","libgphoto2-2_5_18-release","libgphoto2-2_5_17-release","libgphoto2-2_5_16-release","libgphoto2-2_5_15-release","libgphoto2-2_5_14-release","libgphoto2-2_5_13-release","libgphoto2-2_5_12-release","libgphoto2-2_5_11-release","libgphoto2-2_5_10-release","libgphoto2-2_5_9-release","libgphoto2-2_5_8-release","libgphoto2-2_5_7-release","libgphoto2-2_5_6-release","libgphoto2-2_5_5_1-release","libgphoto2-2_5_5-release","libgphoto2-2_5_4-release","libgphoto2-2_5_3_1-release","libgphoto2-2_5_3-release","libgphoto2-2_5_2-release","libgphoto2-2_5_1_1-release","libgphoto2-2_5_1-release","libgphoto2-2_5_0-release"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-40338.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L"}]}