libjpeg-turbo version 2.0.90 is vulnerable to a heap-buffer-overflow vulnerability in decompress_smooth_data in jdcoefct.c. https://bugzilla.redhat.com/show_bug.cgi?id=1943797
Created chromium tracking bugs for this issue: Affects: epel-all [bug 2236152] Created libjpeg-turbo tracking bugs for this issue: Affects: fedora-all [bug 2236153] Created mingw-libjpeg-turbo tracking bugs for this issue: Affects: fedora-all [bug 2236154]
Upstream commit: https://github.com/libjpeg-turbo/libjpeg-turbo/commit/ccaba5d7894ecfb5a8f11e48d3f86e1f14d5a469 Upstream issue/PR: https://github.com/libjpeg-turbo/libjpeg-turbo/pull/476 Other references: https://github.com/libjpeg-turbo/libjpeg-turbo/pull/724
Upstream issue: https://github.com/libjpeg-turbo/libjpeg-turbo/issues/459#issuecomment-733720010
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2024:2295 https://access.redhat.com/errata/RHSA-2024:2295