#1134329 libgphoto2: CVE-2026-40333 CVE-2026-40334 CVE-2026-40335 CVE-2026-40336 CVE-2026-40338 CVE-2026-40339 CVE-2026-40340 CVE-2026-40341

Package:
src:libgphoto2
Source:
src:libgphoto2
Submitter:
Salvatore Bonaccorso
Date:
2026-10-06 13:07:02 UTC
Severity:
normal
Tags:
#1134329#5
Date:
2026-04-18 18:32:03 UTC
From:
To:
Hi,

The following vulnerabilities were published for libgphoto2.

CVE-2026-40333[0]:
| libgphoto2 is a camera access and control library. In versions up to
| and including 2.5.33, two functions in camlibs/ptp2/ptp-pack.c
| accept a data pointer but no length parameter, performing unbounded
| reads. Their callers in ptp_unpack_EOS_events() have xsize available
| but never pass it, leaving both functions unable to validate reads
| against the actual buffer boundary. Commit
| 1817ecead20c2aafa7549dac9619fe38f47b2f53 patches the issue.


CVE-2026-40334[1]:
| libgphoto2 is a camera access and control library. In versions up to
| and including 2.5.33, a missing null terminator exists in
| ptp_unpack_Canon_FE() in camlibs/ptp2/ptp-pack.c (line 1377). The
| function copies a filename into a 13-byte buffer using strncpy
| without explicitly null-terminating the result. If the source data
| is exactly 13 bytes with no null terminator, the buffer is left
| unterminated, leading to out-of-bounds reads in any subsequent
| string operation. Commit 259fc7d3bfe534ce4b114c464f55b448670ab873
| patches the issue.


CVE-2026-40335[2]:
| libgphoto2 is a camera access and control library. Versions up to
| and including 2.5.33 have an out-of-bounds read in
| `ptp_unpack_DPV()` in `camlibs/ptp2/ptp-pack.c` (lines 622–629). The
| UINT128 and INT128 cases advance `*offset += 16` without verifying
| that 16 bytes remain in the buffer. The entry check at line 609 only
| guarantees `*offset < total` (at least 1 byte available), leaving up
| to 15 bytes unvalidated. Commit
| 433bde9888d70aa726e32744cd751d7dbe94379a patches the issue.


CVE-2026-40336[3]:
| libgphoto2 is a camera access and control library. Versions up to
| and including 2.5.33 have a memory leak in `ptp_unpack_Sony_DPD()`
| in `camlibs/ptp2/ptp-pack.c` (lines 884–885). When processing a
| secondary enumeration list (introduced in 2024+ Sony cameras), the
| function overwrites dpd->FORM.Enum.SupportedValue with a new
| calloc() without freeing the previous allocation from line 857. The
| original array and any string values it contains are leaked on every
| property descriptor parse. Commit
| 404ff02c75f3cb280196fc260a63c4d26cf1a8f6 fixes the issue.


CVE-2026-40338[4]:
| libgphoto2 is a camera access and control library. Versions up to
| and including 2.5.33 have an out-of-bounds read in the
| PTP_DPFF_Enumeration case of `ptp_unpack_Sony_DPD()` in
| `camlibs/ptp2/ptp-pack.c` (line 856). The function reads a 2-byte
| enumeration count N via `dtoh16o(data, *poffset)` without verifying
| that 2 bytes remain in the buffer. The standard `ptp_unpack_DPD()`
| at line 704 has this exact check, confirming the Sony variant
| omitted it by oversight. Commit
| 3b9f9696be76ae51dca983d9dd8ce586a2561845 fixes the issue.


CVE-2026-40339[5]:
| libgphoto2 is a camera access and control library. Versions up to
| and including 2.5.33 have an out-of-bounds read in
| `ptp_unpack_Sony_DPD()` in `camlibs/ptp2/ptp-pack.c` (line 842). The
| function reads the FormFlag byte via `dtoh8o(data, *poffset)`
| without a prior bounds check. The standard `ptp_unpack_DPD()` at
| lines 686–687 correctly validates `*offset + sizeof(uint8_t) >
| dpdlen` before this same read, but the Sony variant omits this check
| entirely. Commit 09f8a940b1e418b5693f5c11e3016a1ad2cea62d fixes the
| issue.


CVE-2026-40340[6]:
| libgphoto2 is a camera access and control library. Versions up to
| and including 2.5.33 have an out-of-bounds read vulnerability in
| `ptp_unpack_OI()` in `camlibs/ptp2/ptp-pack.c` (lines 530–563). The
| function validates `len < PTP_oi_SequenceNumber` (i.e., len < 48)
| but subsequently accesses offsets 48–56, up to 9 bytes beyond the
| validated boundary, via the Samsung Galaxy 64-bit objectsize
| detection heuristic. Commit 7c7f515bc88c3d0c4098ac965d313518e0ccbe33
| fixes the issue.


CVE-2026-40341[7]:
| libgphoto2 is a camera access and control library. In versions up to
| and including 2.5.33, an out of bound read in
| ptp_unpack_EOS_FocusInfoEx could be used to crash libgphoto2 when
| processing input from untrusted USB devices. Commit
| c385b34af260595dfbb5f9329526be5158985987 contains a patch. No known
| workarounds are available.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-40333
https://www.cve.org/CVERecord?id=CVE-2026-40333
[1] https://security-tracker.debian.org/tracker/CVE-2026-40334
https://www.cve.org/CVERecord?id=CVE-2026-40334
[2] https://security-tracker.debian.org/tracker/CVE-2026-40335
https://www.cve.org/CVERecord?id=CVE-2026-40335
[3] https://security-tracker.debian.org/tracker/CVE-2026-40336
https://www.cve.org/CVERecord?id=CVE-2026-40336
[4] https://security-tracker.debian.org/tracker/CVE-2026-40338
https://www.cve.org/CVERecord?id=CVE-2026-40338
[5] https://security-tracker.debian.org/tracker/CVE-2026-40339
https://www.cve.org/CVERecord?id=CVE-2026-40339
[6] https://security-tracker.debian.org/tracker/CVE-2026-40340
https://www.cve.org/CVERecord?id=CVE-2026-40340
[7] https://security-tracker.debian.org/tracker/CVE-2026-40341
https://www.cve.org/CVERecord?id=CVE-2026-40341

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1134329#10
Date:
2026-10-06 13:06:24 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
libgphoto2, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1134329@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Ferenc Wágner <wferi@debian.org> (supplier of updated libgphoto2 package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Tue, 06 Oct 2026 14:23:31 +0200
Source: libgphoto2
Architecture: source
Version: 2.5.34-1
Distribution: unstable
Urgency: medium
Maintainer: Debian PhotoTools Maintainers <pkg-phototools-devel@alioth-lists.debian.net>
Changed-By: Ferenc Wágner <wferi@debian.org>
Closes: 1134329
Changes:
 libgphoto2 (2.5.34-1) unstable; urgency=medium
 .
   * [8fb3b5b] New upstream version 2.5.34 (Closes: #1134329)
     Contains fixes for CVE-2026-40333, CVE-2026-40334, CVE-2026-40335,
     CVE-2026-40336, CVE-2026-40338, CVE-2026-40339, CVE-2026-40340 and
     CVE-2026-40341.
   * [988af35] Update Standards-Version to 4.7.4 (no changes required)
   * [da497dd] Update watch file to version 5
   * [1254f9b] Adapt to new Lintian override format
Checksums-Sha1:
 ebd24001cdffa13ad1a7ef1d7c22c27cea0d0c0c 2890 libgphoto2_2.5.34-1.dsc
 5e94f98f2754def5b098cc9f78695504d4b28198 7086120 libgphoto2_2.5.34.orig.tar.xz
 7b5f057495d5f6d7c3bfcb4827f9bf424850de35 833 libgphoto2_2.5.34.orig.tar.xz.asc
 a67298185d09971fa8474a4ac065a1391051e716 100628 libgphoto2_2.5.34-1.debian.tar.xz
 d1e80d718d752a0ed9164b4443902d9bb2a124c4 12768 libgphoto2_2.5.34-1_amd64.buildinfo
Checksums-Sha256:
 9923b644f15a2b1767241620f7215bdb8195eaf6b90fc111caf0e2d02b5d02e2 2890 libgphoto2_2.5.34-1.dsc
 51993f5d9bfb6b4e5925cbbe5883085791bff6f81bcacb8ffe1b783ce76d586a 7086120 libgphoto2_2.5.34.orig.tar.xz
 3d76e51251b1d727dac1e044498f5c9544509e3e35bfcd716a395aed714f8a78 833 libgphoto2_2.5.34.orig.tar.xz.asc
 13a183d04005e4a28880919ef89617e6f801f1f9540210ac159a4488f9ef4923 100628 libgphoto2_2.5.34-1.debian.tar.xz
 77a164b583ccb7287c6116bcedb276a6bb360e9141bfeb3f0c198a3a72df2e3a 12768 libgphoto2_2.5.34-1_amd64.buildinfo
Files:
 05f63f7d90903426f93b2e1e41050966 2890 libs optional libgphoto2_2.5.34-1.dsc
 9fe4fc9f57ac75ae2054ec2a6c369c37 7086120 libs optional libgphoto2_2.5.34.orig.tar.xz
 ea8a81ffc564d985859cd54fdb926e4f 833 libs optional libgphoto2_2.5.34.orig.tar.xz.asc
 246370af012ff954dbe6567448d6e24b 100628 libs optional libgphoto2_2.5.34-1.debian.tar.xz
 e9d9d3faa42f033406d442248e04bc29 12768 libs optional libgphoto2_2.5.34-1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEwddEx0RNIUL7eugtOsj3Fkd+2yMFAmrE6OIACgkQOsj3Fkd+
2yMRrQ//bsACj2itWNjSMSoBkjZ7WNKhBfwC5OTVuNoadnTrY9xj4qoH0TUFz71q
LOL9GVXqNqXhANl+DWlRuDklGmDUMsbw4uo9+3NdTl3kDE+XVHmbTcWf3j7vYLqn
gTGrdbIAILT3nWDHhp5ODJmAnxYWdwJpEJ7d+ATS9Lrkt7j58MzaDQSKjJhM88pq
WJwst+AatKowiUtdhjQEqTisskLnTdKx3DWO8yVHi/yfMwjYdK0APZwV6aaLgrxt
tLQ8W8m94lspxxskPJ1esRECQ6D9RRSYbTCNXho8oEq0CxKWXxaxzPprl/Z7G+QN
QAFOP1QP5/xvsmQ23qWwsDbYMsZm/Gr7njpAfZU6eMpoNDo3hv4ALxd0LGG2fzLX
NcTmmP0RkyZJ/FNi0BIua1BNtW0NdSDqf6W9yGvpi4cRCpS54th4U2Cc7guYJvNA
rmcuvACGJkG9GU0H2r4MusHP2jqFcv3NAbUnLElc+6Fx3ageoSXWEeA+Hmg400uB
0wTg3+KVPgBPP8Vkh0jvKI9ADRpIYqANcffK4RxuxYbjNKakGXNSzrFFWtru6CRQ
v9JZq/fK3m7kpGQ8As8rD1UFjg/JdaIq1IiY7HV+6Cd9bxXSJmnCtifKCr8QS8z+
5BrS8KDRB1QfDnJp+5HPFdkruGkSHj+fIl3ffHd4A8bXc2a1dSY=
=uGdD
-----END PGP SIGNATURE-----