Out-of-Bounds Read Vulnerability in libgphoto2 Affects Camera Access Library
CVE-2026-40340
6.1MEDIUM
What is CVE-2026-40340?
libgphoto2, a widely used camera access and control library, contains an out-of-bounds read vulnerability in the ptp_unpack_OI() function. This issue occurs when the function validates the length, but subsequently accesses memory offsets that exceed the intended boundary, leading to potential exploitation. Persistent users of libgphoto2 should update to the patched version to mitigate this risk. For further details, refer to the related commits and advisories.
Affected Version(s)
libgphoto2 <= 2.5.33
