Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-6192

Опубликовано: 13 апр. 2026
Источник: redhat
CVSS3: 3.3

Описание

A vulnerability was identified in uclouvain openjpeg up to 2.5.4. This impacts the function opj_pi_initialise_encode in the library src/lib/openjp2/pi.c. The manipulation leads to integer overflow. The attack must be carried out locally. The exploit is publicly available and might be used. The identifier of the patch is 839936aa33eb8899bbbd80fda02796bb65068951. It is suggested to install a patch to address this issue.

A flaw was found in uclouvain openjpeg. A local attacker can exploit an integer overflow vulnerability within the opj_pi_initialise_encode function. This manipulation can lead to a Denial of Service (DoS), making the affected system or application unavailable.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10openjpeg2Fix deferred
Red Hat Enterprise Linux 7openjpeg2Not affected
Red Hat Enterprise Linux 8openjpeg2Not affected
Red Hat Enterprise Linux 9openjpeg2Not affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=2457931uclouvain/openjpeg: OpenJPEG: Denial of Service via integer overflow in opj_pi_initialise_encode

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 3.3
ubuntu
4 месяца назад

A vulnerability was identified in uclouvain openjpeg up to 2.5.4. This impacts the function opj_pi_initialise_encode in the library src/lib/openjp2/pi.c. The manipulation leads to integer overflow. The attack must be carried out locally. The exploit is publicly available and might be used. The identifier of the patch is 839936aa33eb8899bbbd80fda02796bb65068951. It is suggested to install a patch to address this issue.

CVSS3: 3.3
nvd
4 месяца назад

A vulnerability was identified in uclouvain openjpeg up to 2.5.4. This impacts the function opj_pi_initialise_encode in the library src/lib/openjp2/pi.c. The manipulation leads to integer overflow. The attack must be carried out locally. The exploit is publicly available and might be used. The identifier of the patch is 839936aa33eb8899bbbd80fda02796bb65068951. It is suggested to install a patch to address this issue.

CVSS3: 3.3
debian
4 месяца назад

A vulnerability was identified in uclouvain openjpeg up to 2.5.4. This ...

CVSS3: 3.3
github
4 месяца назад

A vulnerability was identified in uclouvain openjpeg up to 2.5.4. This impacts the function opj_pi_initialise_encode in the library src/lib/openjp2/pi.c. The manipulation leads to integer overflow. The attack must be carried out locally. The exploit is publicly available and might be used. The identifier of the patch is 839936aa33eb8899bbbd80fda02796bb65068951. It is suggested to install a patch to address this issue.

3.3 Low

CVSS3