Out-of-Bounds Read Vulnerability in libgphoto2 Affects Camera Access Library
CVE-2026-40340

6.1MEDIUM

Key Information:

Vendor

Gphoto

Vendor
CVE Published:
17 April 2026

What is CVE-2026-40340?

libgphoto2, a widely used camera access and control library, contains an out-of-bounds read vulnerability in the ptp_unpack_OI() function. This issue occurs when the function validates the length, but subsequently accesses memory offsets that exceed the intended boundary, leading to potential exploitation. Persistent users of libgphoto2 should update to the patched version to mitigate this risk. For further details, refer to the related commits and advisories.

Affected Version(s)

libgphoto2 <= 2.5.33

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.