CVE-2025-54874
Published: August 6, 2025Last modified: August 6, 2025
Description
OpenJPEG is an open-source JPEG 2000 codec. In OpenJPEG 2.5.3 and earlier, a call to opj_jp2_read_header may lead to OOB heap memory write when the data stream p_stream is too short and p_image is not initialized.
Status
Product | Release | Package | Status |
---|---|---|---|
Alpaquita Linux | 23 LTS | openjpeg | Not affected (2.5.0-r0) |
25 LTS | openjpeg | Vulnerable (2.5.3-r0) | |
Stream | openjpeg | Vulnerable (2.5.2-r0) |