OpenJPEG is an open-source JPEG 2000 codec. In OpenJPEG 2.5.3 and earlier, a call to opj_jp2_read_header may lead to OOB heap memory write when the data stream p_stream is too short and p_image is not initialized.
I believe that this issue was introduced in openjpeg 2.5.1, see https://github.com/uclouvain/openjpeg/pull/1573 and so does not apply to earlier versions of openjpeg
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2025:13944 https://access.redhat.com/errata/RHSA-2025:13944