โ† All reports

The libgphoto2 library has multiple vulnerabilities in versions up to 2.5.33 that could lead to memory leaks, out-of-bounds reads, and crashes when processing camera data.

CybersecurityApr 18, 2026score 0.178 posts ยท 0 replies across 1 instances
Multiple vulnerabilities were reported in the libgphoto2 library, affecting versions up to 2.5.33. These include memory leaks, out-of-bounds reads, and missing null terminators, which could lead to crashes or security risks when processing camera data. The vulnerabilities were disclosed on 2026-04-17.

Claims

The libgphoto2 library has multiple vulnerabilities in versions up to 2.5.33 that could lead to memory leaks, out-of-bounds reads, and crashes when processing camera data.
Parent: Software SecurityEntity: libgphoto2Impact: negativeDate: Apr 18, 2026Target: The security of the libgphoto2 library

Source posts

@[email protected]
๐Ÿšจ EUVD-2026-23581 ๐Ÿ“Š Score: 6.1/10 (CVSS v3.1) ๐Ÿ“ฆ Product: libgphoto2 ๐Ÿข Vendor: gphoto ๐Ÿ“… Updated: 2026-04-17 ๐Ÿ“ libgphoto2 is a camera access and control library. In versions up to and including 2.5.33, two functions in camlibs/ptp2/ptp-pack.c accept a data pointer but no length parameter, performing unbounded reads. Their callers in ptp_unpack_EOS_events() have xsi... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-23581 #cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 18, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
๐Ÿšจ EUVD-2026-23583 ๐Ÿ“Š Score: 3.5/10 (CVSS v3.1) ๐Ÿ“ฆ Product: libgphoto2 ๐Ÿข Vendor: gphoto ๐Ÿ“… Updated: 2026-04-17 ๐Ÿ“ libgphoto2 is a camera access and control library. In versions up to and including 2.5.33, a missing null terminator exists in ptp_unpack_Canon_FE() in camlibs/ptp2/ptp-pack.c (line 1377). The function copies a filename into a 13-byte buffer using strncpy ... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-23583 #cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 18, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
๐Ÿšจ EUVD-2026-23586 ๐Ÿ“Š Score: 5.2/10 (CVSS v3.1) ๐Ÿ“ฆ Product: libgphoto2 ๐Ÿข Vendor: gphoto ๐Ÿ“… Updated: 2026-04-17 ๐Ÿ“ libgphoto2 is a camera access and control library. Versions up to and including 2.5.33 have an out-of-bounds read in `ptp_unpack_DPV()` in `camlibs/ptp2/ptp-pack.c` (lines 622โ€“629). The UINT128 and INT128 cases advance `*offset += 16` without verifying tha... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-23586 #cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 18, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
๐Ÿšจ EUVD-2026-23587 ๐Ÿ“Š Score: 2.4/10 (CVSS v3.1) ๐Ÿ“ฆ Product: libgphoto2 ๐Ÿข Vendor: gphoto ๐Ÿ“… Updated: 2026-04-17 ๐Ÿ“ libgphoto2 is a camera access and control library. Versions up to and including 2.5.33 have a memory leak in `ptp_unpack_Sony_DPD()` in `camlibs/ptp2/ptp-pack.c` (lines 884โ€“885). When processing a secondary enumeration list (introduced in 2024+ Sony camera... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-23587 #cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 18, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
๐Ÿšจ EUVD-2026-23605 ๐Ÿ“Š Score: 5.2/10 (CVSS v3.1) ๐Ÿ“ฆ Product: libgphoto2 ๐Ÿข Vendor: gphoto ๐Ÿ“… Updated: 2026-04-17 ๐Ÿ“ libgphoto2 is a camera access and control library. Versions up to and including 2.5.33 have an out-of-bounds read in the PTP_DPFF_Enumeration case of `ptp_unpack_Sony_DPD()` in `camlibs/ptp2/ptp-pack.c` (line 856). The function reads a 2-byte enumeration c... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-23605 #cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 18, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
๐Ÿšจ EUVD-2026-23607 ๐Ÿ“Š Score: 5.2/10 (CVSS v3.1) ๐Ÿ“ฆ Product: libgphoto2 ๐Ÿข Vendor: gphoto ๐Ÿ“… Updated: 2026-04-17 ๐Ÿ“ libgphoto2 is a camera access and control library. Versions up to and including 2.5.33 have an out-of-bounds read in `ptp_unpack_Sony_DPD()` in `camlibs/ptp2/ptp-pack.c` (line 842). The function reads the FormFlag byte via `dtoh8o(data, *poffset)` without ... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-23607 #cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 18, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
๐Ÿšจ EUVD-2026-23609 ๐Ÿ“Š Score: 6.1/10 (CVSS v3.1) ๐Ÿ“ฆ Product: libgphoto2 ๐Ÿข Vendor: gphoto ๐Ÿ“… Updated: 2026-04-17 ๐Ÿ“ libgphoto2 is a camera access and control library. Versions up to and including 2.5.33 have an out-of-bounds read vulnerability in `ptp_unpack_OI()` in `camlibs/ptp2/ptp-pack.c` (lines 530โ€“563). The function validates `len < PTP_oi_SequenceNumber` (i.e., l... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-23609 #cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 18, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
๐Ÿšจ EUVD-2026-23611 ๐Ÿ“Š Score: 3.5/10 (CVSS v3.1) ๐Ÿ“ฆ Product: libgphoto2 ๐Ÿข Vendor: gphoto ๐Ÿ“… Updated: 2026-04-17 ๐Ÿ“ libgphoto2 is a camera access and control library. In versions up to and including 2.5.33, an out of bound read in ptp_unpack_EOS_FocusInfoEx could be used to crash libgphoto2 when processing input from untrusted USB devices. Commit c385b34af260595dfbb5f93... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-23611 #cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 18, 2026
#cybersecurity#infosec#euvd#cve#vulnerability