CVE Explorer
CVE-2026-40336
libgphoto2 is a camera access and control library. Versions up to and including 2.5.33 have a memory leak in `ptp_unpack_Sony_DPD()` in `camlibs/ptp2/ptp-pack.c` (lines 884–885). When processing a secondary enumeration list (introduced in 2024+ Sony cameras), the function overwrites dpd->FORM.Enum.SupportedValue with a new calloc() without freeing the previous allocation from line 857. The original array and any string values it contains are leaked on every property descriptor parse. Commit 404f
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"libgphoto2","vendor":"gphoto","versions":[{"status":"affected","version":"<= 2.5.33"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:da0adb5ce1af0ceaf4edf6d68c7dba44d89a05e0cb199613c166d36810bc0f37 · sha256:61948b035fdd0b8e… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"PHYSICAL","availabilityImpact":"LOW","baseScore":2.4,"baseSeverity":"LOW","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:da0adb5ce1af0ceaf4edf6d68c7dba44d89a05e0cb199613c166d36810bc0f37 · sha256:61948b035fdd0b8e… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-401","description":"CWE-401: Missing Release of Memory after Effective Lifetime","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:da0adb5ce1af0ceaf4edf6d68c7dba44d89a05e0cb199613c166d36810bc0f37 · sha256:61948b035fdd0b8e… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"name":"https://github.com/gphoto/libgphoto2/commit/404ff02c75f3cb280196fc260a63c4d26cf1a8f6","tags":["x_refsource_MISC"],"url":"https://github.com/gphoto/libgphoto2/commit/404ff02c75f3cb280196fc260a63c4d26cf1a8f6"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:da0adb5ce1af0ceaf4edf6d68c7dba44d89a05e0cb199613c166d36810bc0f37 · sha256:61948b035fdd0b8e… · /containers/cna/references/1
{"name":"https://github.com/gphoto/libgphoto2/security/advisories/GHSA-g8xw-p5wj-mrxv","tags":["x_refsource_CONFIRM"],"url":"https://github.com/gphoto/libgphoto2/security/advisories/GHSA-g8xw-p5wj-mrxv"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:da0adb5ce1af0ceaf4edf6d68c7dba44d89a05e0cb199613c166d36810bc0f37 · sha256:61948b035fdd0b8e… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.