[ubuntu/jammy-security] libgphoto2 2.5.27-1ubuntu0.1 (Accepted)

Marc Deslauriers marc.deslauriers at canonical.com
Wed Jul 22 13:06:20 UTC 2026


libgphoto2 (2.5.27-1ubuntu0.1) jammy-security; urgency=medium

  * SECURITY UPDATE: unbounded reads via data pointer but no length parameter
    - debian/patches/CVE-2026-40333.patch: Fixed EOS ImageFormat/CustomFuncEx
      Parsers Lack Length Parameter in camlibs/ptp2/ptp-pack.c.
    - CVE-2026-40333
  * SECURITY UPDATE: OOB read via missing null terminator
    - debian/patches/CVE-2026-40334.patch: Fixed Canon FolderEntry Missing Null
      Termination in camlibs/ptp2/ptp-pack.c.
    - CVE-2026-40334
  * SECURITY UPDATE: out-of-bounds read
    - debian/patches/CVE-2026-40335.patch: Fixed UINT128/INT128 Unchecked
      Offset in camlibs/ptp2/ptp-pack.c.
    - CVE-2026-40335
  * SECURITY UPDATE: out-of-bounds read in PTP_DPFF_Enumeration
    - debian/patches/CVE-2026-40338.patch: Fixed Sony DPD Enum Count OOB Read
      in camlibs/ptp2/ptp-pack.c.
    - CVE-2026-40338
  * SECURITY UPDATE: out-of-bounds read in ptp_unpack_Sony_DPD()
    - debian/patches/CVE-2026-40339.patch: Fixed Sony DPD FormFlag OOB Read in
      camlibs/ptp2/ptp-pack.c.
    - CVE-2026-40339
  * SECURITY UPDATE: out-of-bounds read vulnerability in ptp_unpack_OI()
    - debian/patches/CVE-2026-40340.patch: Fixed ObjectInfo Parser OOB Read in
      camlibs/ptp2/ptp-pack.c.
    - CVE-2026-40340
  * SECURITY UPDATE: out of bound read in ptp_unpack_EOS_FocusInfoEx
    - debian/patches/CVE-2026-40341.patch: Fixed OOB read in
      ptp_unpack_EOS_FocusInfoEx in camlibs/ptp2/ptp-pack.c.
    - CVE-2026-40341

Date: 2026-07-16 12:00:44.055557+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
https://launchpad.net/ubuntu/+source/libgphoto2/2.5.27-1ubuntu0.1
-------------- next part --------------
Sorry, changesfile not available.


More information about the jammy-changes mailing list