Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-54874

Опубликовано: 05 авг. 2025
Источник: redhat
CVSS3: 8

Описание

OpenJPEG is an open-source JPEG 2000 codec. In OpenJPEG 2.5.3 and earlier, a call to opj_jp2_read_header may lead to OOB heap memory write when the data stream p_stream is too short and p_image is not initialized.

An out-of-bounds heap memory write (OOB) flaw was found in OpenJPEG. A call to opj_jp2_read_header may lead to an OOB heap memory write when the data stream p_stream is too short and p_image is not initialized.

Отчет

This vulnerability is Important rather than Moderate because it allows a malformed or truncated data stream to trigger a heap-based out-of-bounds (OOB) write, which directly corrupts memory. Unlike read-based issues or null dereference crashes that typically lead to denial of service, an OOB write has the potential to alter program control flow, leading to arbitrary code execution under certain conditions. The affected pointer p_image is dereferenced without verifying the success of the header parsing routine, and if it's left uninitialized due to a parsing failure, writing to it results in undefined behavior.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6openjpegOut of support scope
Red Hat Enterprise Linux 7openjpegNot affected
Red Hat Enterprise Linux 7openjpeg2Not affected
Red Hat Enterprise Linux 8openjpeg2Not affected
Red Hat Enterprise Linux 9openjpeg2Not affected
Red Hat Enterprise Linux AI (RHEL AI)libpdfiumNot affected
Red Hat Enterprise Linux 10openjpeg2FixedRHSA-2025:1394418.08.2025

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-457
https://bugzilla.redhat.com/show_bug.cgi?id=2386543openjpeg: OpenJPEG OOB heap memory write

8 High

CVSS3

Связанные уязвимости

ubuntu
23 дня назад

OpenJPEG is an open-source JPEG 2000 codec. In OpenJPEG 2.5.3 and earlier, a call to opj_jp2_read_header may lead to OOB heap memory write when the data stream p_stream is too short and p_image is not initialized.

nvd
23 дня назад

OpenJPEG is an open-source JPEG 2000 codec. In OpenJPEG 2.5.3 and earlier, a call to opj_jp2_read_header may lead to OOB heap memory write when the data stream p_stream is too short and p_image is not initialized.

debian
23 дня назад

OpenJPEG is an open-source JPEG 2000 codec. In OpenJPEG 2.5.3 and earl ...

oracle-oval
11 дней назад

ELSA-2025-13944: openjpeg2 security update (IMPORTANT)

8 High

CVSS3