libgphoto2 is a camera access and control library.
libgphoto2 is a camera access and control library. Versions up to and including 2.5.33 have an out-of-bounds read in `ptp_unpack_Sony_DPD()` in `camlibs/ptp2/ptp-pack.c` (line 842). The function reads the FormFlag byte via `dtoh8o(data, *poffset)` without a prior bounds check. The standard `ptp_unpack_DPD()` at lines 686–687 correctly validates `*offset + sizeof(uint8_t) > dpdlen` before this same read, but the Sony variant omits this check entirely. Commit 09f8a940b1e418b5693f5c11e3016a1ad2cea62d fixes the issue.
AI Analysis
Technical Summary
The vulnerability in libgphoto2 arises from an out-of-bounds read in the ptp_unpack_Sony_DPD() function located in camlibs/ptp2/ptp-pack.c. Unlike the standard ptp_unpack_DPD() function, which performs a bounds check before reading the FormFlag byte, the Sony-specific variant omits this validation, leading to a potential out-of-bounds memory read. This affects versions up to and including 2.5.33. The issue was addressed in commit 09f8a940b1e418b5693f5c11e3016a1ad2cea62d.
Potential Impact
An out-of-bounds read vulnerability can lead to information disclosure or application instability. According to the CVSS vector, the vulnerability requires physical access (AV:P), has low attack complexity, no privileges required, no user interaction, and impacts confidentiality (high) and availability (low). There are no known exploits in the wild.
Mitigation Recommendations
A fix is available as the issue was resolved in commit 09f8a940b1e418b5693f5c11e3016a1ad2cea62d. Users should upgrade libgphoto2 to a version later than 2.5.33 or apply the patch provided by their distribution. Since this is not a cloud service, remediation is the responsibility of the user or system administrator.
libgphoto2 is a camera access and control library.
Description
libgphoto2 is a camera access and control library. Versions up to and including 2.5.33 have an out-of-bounds read in `ptp_unpack_Sony_DPD()` in `camlibs/ptp2/ptp-pack.c` (line 842). The function reads the FormFlag byte via `dtoh8o(data, *poffset)` without a prior bounds check. The standard `ptp_unpack_DPD()` at lines 686–687 correctly validates `*offset + sizeof(uint8_t) > dpdlen` before this same read, but the Sony variant omits this check entirely. Commit 09f8a940b1e418b5693f5c11e3016a1ad2cea62d fixes the issue.
CVSS v3.1
Score 5.2medium
Affected software
pkg:deb/ubuntu/[email protected]?arch=source&distro=trustypkg:deb/ubuntu/[email protected]?arch=source&distro=xenialpkg:deb/ubuntu/[email protected]?arch=source&distro=bionicpkg:deb/ubuntu/[email protected]?arch=source&distro=focalpkg:deb/ubuntu/[email protected]?arch=source&distro=jammypkg:deb/ubuntu/[email protected]?arch=source&distro=noblepkg:deb/ubuntu/[email protected]?arch=source&distro=questingpkg:deb/ubuntu/[email protected]?arch=source&distro=resoluteRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in libgphoto2 arises from an out-of-bounds read in the ptp_unpack_Sony_DPD() function located in camlibs/ptp2/ptp-pack.c. Unlike the standard ptp_unpack_DPD() function, which performs a bounds check before reading the FormFlag byte, the Sony-specific variant omits this validation, leading to a potential out-of-bounds memory read. This affects versions up to and including 2.5.33. The issue was addressed in commit 09f8a940b1e418b5693f5c11e3016a1ad2cea62d.
Potential Impact
An out-of-bounds read vulnerability can lead to information disclosure or application instability. According to the CVSS vector, the vulnerability requires physical access (AV:P), has low attack complexity, no privileges required, no user interaction, and impacts confidentiality (high) and availability (low). There are no known exploits in the wild.
Mitigation Recommendations
A fix is available as the issue was resolved in commit 09f8a940b1e418b5693f5c11e3016a1ad2cea62d. Users should upgrade libgphoto2 to a version later than 2.5.33 or apply the patch provided by their distribution. Since this is not a cloud service, remediation is the responsibility of the user or system administrator.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- UBUNTU-CVE-2026-40339
- Osv Schema Version
- 1.7.0
- Aliases
- []
- Ecosystems
- ["Ubuntu:14.04:LTS","Ubuntu:16.04:LTS","Ubuntu:18.04:LTS","Ubuntu:20.04:LTS","Ubuntu:22.04:LTS","Ubuntu:24.04:LTS","Ubuntu:25.10","Ubuntu:26.04:LTS"]
- Database Specific Severity
- null
- Cvss Version
- 3.1
Threat ID: 6a58b4c668715ace43daac3f
Added to database: 07/16/2026, 10:39:02 UTC
Last enriched: 07/16/2026, 13:19:47 UTC
Last updated: 07/31/2026, 19:22:58 UTC
Views: 9
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.