libjpeg-turbo 2.0.4, and mozjpeg 4.0.0, has a heap-based buffer over-read in get_rgb_row() in rdppm.c via a malformed PPM input file. Reference: https://github.com/libjpeg-turbo/libjpeg-turbo/issues/433 Upstream commit: https://github.com/libjpeg-turbo/libjpeg-turbo/commit/3de15e0c344d11d4b90f4a47136467053eb2d09a
Created libjpeg-turbo tracking bugs for this issue: Affects: fedora-all [bug 1847159] Created mingw-libjpeg-turbo tracking bugs for this issue: Affects: fedora-all [bug 1847160]
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2025:7540 https://access.redhat.com/errata/RHSA-2025:7540