Bug 2533857 (CVE-2026-39919) - CVE-2026-39919 ghostscript: ghostscript: Heap buffer overflow via JPEG 2000 output adapter
Summary: CVE-2026-39919 ghostscript: ghostscript: Heap buffer overflow via JPEG 2000 o...
Keywords:
Status: NEW
Alias: CVE-2026-39919
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2537359
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-15 14:51 UTC by OSIDB Bzimport
Modified: 2026-09-21 10:48 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-15 14:51:06 UTC
Ghostscript before 10.08.0 contains a heap-based buffer overflow vulnerability in the JPEG 2000 output adapter (base/sjpx_openjpeg.c) that allows attackers to cause memory corruption by supplying a crafted PDF containing a JPEG 2000 image with mismatched component subsampling factors. When image components declare different subsampling values, the non-samescale sub-byte-depth output path allocates a row buffer sized for packed output but writes a full byte per output column regardless of bit depth, overflowing the allocation and corrupting internal chunk-allocator metadata to achieve code execution.


Note You need to log in before you can comment on or make changes to this bug.