Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

SUSE 16-0 Jasper Moderate Security Fix 2026-20200-1 Update Released

suse
Calendar Grey February 3, 2026
Dist Suse Esm H88
Update for jasper fixes multiple security issues including memory access and coding errors. Install patches promptly.
An update that solves three vulnerabilities can now be installed.

Summary

## This update for jasper fixes the following issues: Update to 4.2.8: * CVE-2025-8837: Fixed a bug in the JPC decoder that could cause bad memory accesses if the debug level is set sufficiently high (bsc#1247901). * CVE-2025-8836: Added some missing range checking on several coding parameters in the JPC encoder (bsc#1247902). * CVE-2025-8835: Added a check for a missing color component in the jas_image_chclrspc function (bsc#1247904). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-223=1 * SUSE Linux Enterprise Server for SAP Applications 16.0 zypper in -t patch SUSE-SLES-16.0-223=1

References

* bsc#1247901

* bsc#1247902

* bsc#1247904

Cross-

* CVE-2025-8835

* CVE-2025-8836

* CVE-2025-8837

CVSS scores:

* CVE-2025-8835 ( SUSE ): 6.8

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

* CVE-2025-8835 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

* CVE-2025-8835 ( NVD ): 1.9

CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

* CVE-2025-8835 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

* CVE-2025-8835 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

* CVE-2025-8836 ( SUSE ): 2.0

CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

Announcement ID: SUSE-SU-2026:20200-1
Release Date: 2026-01-30T09:59:14Z
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here