Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2026:20842-1

Опубликовано: 29 мая 2026
Источник: suse-cvrf

Описание

Security update for openjpeg2

This update for openjpeg2 fixes the following issue

  • CVE-2025-54874: openjpeg: missing error check can lead to the use of an uninitialized pointer and cause an out-of- bounds heap memory write (bsc#1247650).

Список пакетов

openSUSE Leap 16.0
libopenjp2-7-2.5.3-160000.4.1
libopenjp2-7-x86-64-v3-2.5.3-160000.4.1
openjpeg2-2.5.3-160000.4.1
openjpeg2-devel-2.5.3-160000.4.1
openjpeg2-devel-doc-2.5.3-160000.4.1

Описание

OpenJPEG is an open-source JPEG 2000 codec. In OpenJPEG from 2.5.1 through 2.5.3, a call to opj_jp2_read_header may lead to OOB heap memory write when the data stream p_stream is too short and p_image is not initialized.


Затронутые продукты
openSUSE Leap 16.0:libopenjp2-7-2.5.3-160000.4.1
openSUSE Leap 16.0:libopenjp2-7-x86-64-v3-2.5.3-160000.4.1
openSUSE Leap 16.0:openjpeg2-2.5.3-160000.4.1
openSUSE Leap 16.0:openjpeg2-devel-2.5.3-160000.4.1

Ссылки
Уязвимость openSUSE-SU-2026:20842-1