Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 513
Alerts This Week
Warning Icon 1 513

Ubuntu jbig2dec Important Denial of Service Vulnerabilities USN-8582-1

ubuntu
Calendar Grey July 21, 2026
Scroller Ubuntu
Multiple security flaws in jbig2dec identified, leading to possible denial of service attacks in Ubuntu systems.
Several security issues were fixed in jbig2dec.

Summary

Several security issues were fixed in jbig2dec.

Software Description:

- jbig2dec: JBIG2 decoder library

Details:

Zeng Yunxiang and Song Jiaxuan discovered that jbig2dec had an

out-of-bounds read vulnerability in its command-line tool. An attacker

could possibly use this issue to cause jbig2dec to crash, resulting in a

denial of service. This issue only affected Ubuntu 22.04 LTS.

(CVE-2023-46361)

It was discovered that jbig2dec had an integer overflow in the

jbig2_arith_iaid_ctx_new() function. An attacker could possibly use this

issue to cause a denial of service. (CVE-2026-38076)

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 26.04 LTS
  jbig2dec                        0.20-1ubuntu0.26.04.1
  libjbig2dec0                    0.20-1ubuntu0.26.04.1

Ubuntu 24.04 LTS
  jbig2dec                        0.20-1ubuntu0.24.04.1
  libjbig2dec0                    0.20-1ubuntu0.24.04.1

Ubuntu 22.04 LTS
  jbig2dec                        0.19-3ubuntu0.1
  libjbig2dec0                    0.19-3ubuntu0.1

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-8582-1

CVE-2023-46361, CVE-2026-38076

Severity
important
Lowest
Low
Medium
High
Critical

Ubuntu Security Notice USN-8582-1

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.