This bug is triggered when we use opj_decompress with the -t option and its argument set to 1. The latest version v2.5.2 also has this vulnerability. Reproducible: Always Steps to Reproduce: see https://github.com/uclouvain/openjpeg/issues/1564 References: https://github.com/uclouvain/openjpeg/issues/1564 https://github.com/uclouvain/openjpeg/commit/e492644fbded4c820ca55b5e50e598d346e850e8
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2025:7309 https://access.redhat.com/errata/RHSA-2025:7309