Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Several security issues were fixed in jbig2dec.. ========================================================================== Ubuntu Security Notice USN-8582-1 July 21, 2026 jbig2dec vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: Several security issues were fixed in jbig2dec. Software Description: - jbig2dec: JBIG2 decoder library Details: Zeng Yunxiang and Song Jiaxuan discovered that jbig2dec had an out-of-bounds read vulnerability in its command-line tool. An attacker could possibly use this issue to cause jbig2dec to crash, resulting in a denial of service. This issue only affected Ubuntu 22.04 LTS. (CVE-2023-46361) It was discovered that jbig2dec had an integer overflow in the jbig2_arith_iaid_ctx_new() function. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-38076) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS jbig2dec 0.20-1ubuntu0.26.04.1 libjbig2dec0 0.20-1ubuntu0.26.04.1 Ubuntu 24.04 LTS jbig2dec 0.20-1ubuntu0.24.04.1 libjbig2dec0 0.20-1ubuntu0.24.04.1 Ubuntu 22.04 LTS jbig2dec 0.19-3ubuntu0.1 libjbig2dec0 0.19-3ubuntu0.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8582-1 CVE-2023-46361, CVE-2026-38076 Package Information: https://launchpad.net/ubuntu/+source/jbig2dec/0.20-1ubuntu0.26.04.1 https://launchpad.net/ubuntu/+source/jbig2dec/0.20-1ubuntu0.24.04.1 https://launchpad.net/ubuntu/+source/jbig2dec/0.19-3ubuntu0.1 . Multiple security flaws in jbig2dec identified, leading to possible denial of service attacks in Ubuntu systems.. Ubuntu updates, jbig2dec flaws,Ubuntu security, denial of service, vulnerability updates. . Severity: Important. LinuxSecurity.com Team
Several security issues were fixed in jbig2dec.. =========================================================================Ubuntu Security Notice USN-5405-1 May 05, 2022 jbig2dec vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 ESM Summary: Several security issues were fixed in jbig2dec. Software Description: - jbig2dec: JBIG2 decoder library Details: It was discovered that jbig2dec incorrectly handled memory when parsing invalid files. An attacker could use this issue to cause jbig2dec to crash, leading to a denial of service. (CVE-2017-9216) It was discovered that jbig2dec incorrectly handled memory when processing untrusted input. An attacker could use this issue to cause a denial of service, or possibly execute arbitrary code. (CVE-2020-12268) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 ESM: jbig2dec 0.12+20150918-1ubuntu0.1+esm2 libjbig2dec0 0.12+20150918-1ubuntu0.1+esm2 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5405-1 CVE-2017-9216, CVE-2020-12268 . Various vulnerabilities in jbig2dec addressed in Ubuntu 16.04 could result in system crashes or unauthorized code execution.. jbig2dec Update, Ubuntu Security Fix, Security Issues Resolution. . LinuxSecurity.com Team
Two issues have been found in jbig2dec, a JBIG2 decoder library. One issue is related to an overflow with a crafted image file. The other is related to a NULL pointer dereference. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2796-1
An update for jbig2dec is now available for Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: jbig2dec security update Advisory ID: RHSA-2020:3043-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2020:3043 Issue date: 2020-07-21 CVE Names: CVE-2020-12268 ==================================================================== 1. Summary: An update for jbig2dec is now available for Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream E4S (v. 8.0) - aarch64, ppc64le, s390x, x86_64 3. Description: jbig2dec is a decoder implementation of the JBIG2 image compression format. Security Fix(es): * jbig2dec: heap-based buffer overflow in jbig2_image_compose in jbig2_image.c (CVE-2020-12268) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1848518 - CVE-2020-12268 jbig2dec: heap-based buffer overflow in jbig2_image_compose in jbig2_image.c 6. Package List: Red Hat Enterprise Linux AppStream E4S (v.8.0): Source: jbig2dec-0.14-4.el8_0.src.rpm aarch64: jbig2dec-debuginfo-0.14-4.el8_0.aarch64.rpm jbig2dec-debugsource-0.14-4.el8_0.aarch64.rpm jbig2dec-libs-0.14-4.el8_0.aarch64.rpm jbig2dec-libs-debuginfo-0.14-4.el8_0.aarch64.rpm ppc64le: jbig2dec-debuginfo-0.14-4.el8_0.ppc64le.rpm jbig2dec-debugsource-0.14-4.el8_0.ppc64le.rpm jbig2dec-libs-0.14-4.el8_0.ppc64le.rpm jbig2dec-libs-debuginfo-0.14-4.el8_0.ppc64le.rpm s390x: jbig2dec-debuginfo-0.14-4.el8_0.s390x.rpm jbig2dec-debugsource-0.14-4.el8_0.s390x.rpm jbig2dec-libs-0.14-4.el8_0.s390x.rpm jbig2dec-libs-debuginfo-0.14-4.el8_0.s390x.rpm x86_64: jbig2dec-debuginfo-0.14-4.el8_0.i686.rpm jbig2dec-debuginfo-0.14-4.el8_0.x86_64.rpm jbig2dec-debugsource-0.14-4.el8_0.i686.rpm jbig2dec-debugsource-0.14-4.el8_0.x86_64.rpm jbig2dec-libs-0.14-4.el8_0.i686.rpm jbig2dec-libs-0.14-4.el8_0.x86_64.rpm jbig2dec-libs-debuginfo-0.14-4.el8_0.i686.rpm jbig2dec-libs-debuginfo-0.14-4.el8_0.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2020-12268 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2020 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBXxb9sdzjgjWX9erEAQgaxw/+J3gJwY8EBCsYCqBgP8Oy89HmV60dv+zR sYAOvuQPhC/OjtBnmRg0qbsf6r9uX3yPwHH/ZK0RugbsZzX15nSVVsH8psZgJaeW zTJDOn44lbMzJV9pSC+GUjlic07yOYhicLiXEOvFSon0/25198ChcTuRlxYxHKw8 uN/WIzSz+KxfbR7LjU6iPR+1Z5nMBehJ6dBoDnUH6DW0alKoXlkeZiFgGpv9j8JO wnDQAABz2exT+wMlOFNPlnsOB0iKdWqN5f3pjoTmwx7GCaK1MpJW0geqj8cPrLxn vmWnc1ZWJT+HwzERD3Q6FJl52rB8muj/s0lK7oxU+5X0TMxoF+R3PVbMsSPe2K/u VpkO50s2GaI6Nv0Nkv7lWjRMCZ058hdiZUATsYuZ3Tfd3yhKR04xJPVM/qpZfHoT LaYjnEIVxfO575mJBNerT5v/U1GwyY5H6Mxpek5rlOVBOdC44MZr6zp4Cyqz6mcl W9u04WCZ7jsRYT23pD8p9KN3Q8OK+V2E3hPdj9aUgjj9ClCN+3/n+TgjtpWwQTwq rPkJB9SYcVbpGPfxOkjUovRavBuGi0M9gPaU3ufTUG1UDSnJc1/QiPN2E2j/S7si aM3zVJQzX7jyFpYS02ip4CgF5PfQSkBdNw0COhRAEIzONAIoYgN86W9WanJAnnGe MrmWR7MtWwY=mgLK -----END PGP SIGNATURE----- -- RHSA-announce mailing list
An update for jbig2dec is now available for Red Hat Enterprise Linux 8.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: jbig2dec security update Advisory ID: RHSA-2020:2971-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2020:2971 Issue date: 2020-07-16 CVE Names: CVE-2020-12268 ==================================================================== 1. Summary: An update for jbig2dec is now available for Red Hat Enterprise Linux 8.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream EUS (v. 8.1) - aarch64, ppc64le, s390x, x86_64 3. Description: jbig2dec is a decoder implementation of the JBIG2 image compression format. Security Fix(es): * jbig2dec: heap-based buffer overflow in jbig2_image_compose in jbig2_image.c (CVE-2020-12268) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1848518 - CVE-2020-12268 jbig2dec: heap-based buffer overflow in jbig2_image_compose in jbig2_image.c 6. Package List: Red Hat Enterprise Linux AppStream EUS (v.8.1): Source: jbig2dec-0.14-4.el8_1.src.rpm aarch64: jbig2dec-debuginfo-0.14-4.el8_1.aarch64.rpm jbig2dec-debugsource-0.14-4.el8_1.aarch64.rpm jbig2dec-libs-0.14-4.el8_1.aarch64.rpm jbig2dec-libs-debuginfo-0.14-4.el8_1.aarch64.rpm ppc64le: jbig2dec-debuginfo-0.14-4.el8_1.ppc64le.rpm jbig2dec-debugsource-0.14-4.el8_1.ppc64le.rpm jbig2dec-libs-0.14-4.el8_1.ppc64le.rpm jbig2dec-libs-debuginfo-0.14-4.el8_1.ppc64le.rpm s390x: jbig2dec-debuginfo-0.14-4.el8_1.s390x.rpm jbig2dec-debugsource-0.14-4.el8_1.s390x.rpm jbig2dec-libs-0.14-4.el8_1.s390x.rpm jbig2dec-libs-debuginfo-0.14-4.el8_1.s390x.rpm x86_64: jbig2dec-debuginfo-0.14-4.el8_1.i686.rpm jbig2dec-debuginfo-0.14-4.el8_1.x86_64.rpm jbig2dec-debugsource-0.14-4.el8_1.i686.rpm jbig2dec-debugsource-0.14-4.el8_1.x86_64.rpm jbig2dec-libs-0.14-4.el8_1.i686.rpm jbig2dec-libs-0.14-4.el8_1.x86_64.rpm jbig2dec-libs-debuginfo-0.14-4.el8_1.i686.rpm jbig2dec-libs-debuginfo-0.14-4.el8_1.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2020-12268 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2020 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBXxAS6tzjgjWX9erEAQiJ3xAAk3BGn+TuJGYd/f4wsYQ6jrzcqI6MZCPE u+VFtMDoSEUWtMGbNjq7KlTT688XVAeZg3fvElHm3j1mmU/nfWbiAydZ+pVge1g5 U/B+Z6KUJDmkk5Vr1dG7BfFcyd9ve7PDVbMuUxYy8gJ4gzpz6/yeCspSDC6axUOL xmGRr7tjJ3AIKjoobYCrgmV102/P8TI3ugYCfs9gdBKsXS+liNhqlw+P4LgSNxfZ XGYoxcn87M5D6wyFI5cgVvpcexOjClhKJECJS1dzrSnS7YLAaznmV1V2wqUyRod0 a2y5WAl6BXMI4ysxwsd+dq3tIUuMXJoI57MmwwgyPS/R4msnjNj7r3NnvWYdASWp WvRdxWnZa02tM5aRnacANO2mAT8/AeDrULy9tmf1P8RRStG6xoDzRwmSCs0XbQ2P OUS+Bi6N9BE7+is5IYhznB1bD+PmG0skjUL+EulziObP3NYFrYQWeO8nvGbg+R6X 9Be1/L2ILmWmDz0s5za2mFvUUtN53AT5hFETnThM5oWMTB4sSPFS463M+A14olix feWHBo6FrRAE42L7hc8lOa0NvoGtlYYBNCSWMUeGhZ2liMk4lMfMU9poUawALKbq NVV4PPWqiGUmua6FwNPYJP+KyDi0PbqTDQ3oJdNObijVmmeOa/vL67ktd4e95WyN uGMgjDpg9ng=jdHp -----END PGP SIGNATURE----- -- RHSA-announce mailing list
An update for jbig2dec is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: jbig2dec security update Advisory ID: RHSA-2020:2897-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2020:2897 Issue date: 2020-07-13 CVE Names: CVE-2020-12268 ==================================================================== 1. Summary: An update for jbig2dec is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream (v. 8) - aarch64, ppc64le, s390x, x86_64 3. Description: jbig2dec is a decoder implementation of the JBIG2 image compression format. Security Fix(es): * jbig2dec: heap-based buffer overflow in jbig2_image_compose in jbig2_image.c (CVE-2020-12268) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1848518 - CVE-2020-12268 jbig2dec: heap-based buffer overflow in jbig2_image_compose in jbig2_image.c 6. Package List: Red Hat Enterprise Linux AppStream (v.8): Source: jbig2dec-0.14-4.el8_2.src.rpm aarch64: jbig2dec-debuginfo-0.14-4.el8_2.aarch64.rpm jbig2dec-debugsource-0.14-4.el8_2.aarch64.rpm jbig2dec-libs-0.14-4.el8_2.aarch64.rpm jbig2dec-libs-debuginfo-0.14-4.el8_2.aarch64.rpm ppc64le: jbig2dec-debuginfo-0.14-4.el8_2.ppc64le.rpm jbig2dec-debugsource-0.14-4.el8_2.ppc64le.rpm jbig2dec-libs-0.14-4.el8_2.ppc64le.rpm jbig2dec-libs-debuginfo-0.14-4.el8_2.ppc64le.rpm s390x: jbig2dec-debuginfo-0.14-4.el8_2.s390x.rpm jbig2dec-debugsource-0.14-4.el8_2.s390x.rpm jbig2dec-libs-0.14-4.el8_2.s390x.rpm jbig2dec-libs-debuginfo-0.14-4.el8_2.s390x.rpm x86_64: jbig2dec-debuginfo-0.14-4.el8_2.i686.rpm jbig2dec-debuginfo-0.14-4.el8_2.x86_64.rpm jbig2dec-debugsource-0.14-4.el8_2.i686.rpm jbig2dec-debugsource-0.14-4.el8_2.x86_64.rpm jbig2dec-libs-0.14-4.el8_2.i686.rpm jbig2dec-libs-0.14-4.el8_2.x86_64.rpm jbig2dec-libs-debuginfo-0.14-4.el8_2.i686.rpm jbig2dec-libs-debuginfo-0.14-4.el8_2.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2020-12268 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2020 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBXwxBVtzjgjWX9erEAQj/1g/+Lfmi2m1LJaZ4pGgXTniKQhKFS3JbGmpF hnXehKOJU1Apz5vxUfuLdu1X8WN8EvPSGXPfJLD8WaCwAA91EoRCLuSUFyWiXcKd 7WQGUFJwrT5fPPkG0QYUiuW+JBlszRbWIh5+m6dw+3eY1JAtbLtreoRqv15PA2vb Sh2DsYuDvtHZ6JBnNAlxDhFgooUPyo9xd4geIVOoNqtnTh6g9iUpWFge7iwLiUTY UcBpyj1MuhuB9pgrlv7BJTyACizuaZGbEbD4zRmfnq3tiq+31bJR23Z2zat1TBrN cDPqDZ+qZ6UyDBAgl2KGbBV746pc7219PN1ryxgQb11pOwyDTUX1XO43Kfwj0R06 fHTur3YyoUQ1k3snCJ50T7KMAmTfMOjJeCFy97tMk1atKbtWbJYjARowBu/bkGy6 caO8sLgrXm7l9ootPMvaNVQXOXoZMOXwBH7xckn+TanoQYqtD3kxdZ7dQrsZnhd9 b1U1RwDV6OyjRN7Ff3LhyeA5abS3K2GNBgH4jeNSCAQ2N86hA9JVXhQoKhWj4Ecm S37r3k6EbqIh/uwMxtB36JR9K97GxP5vNs4jHqlQ+jQtNWaBnZgQNTlsfrCvRihH FJCfy61P9KhXBkvBFTe98zmeNUa5R4YA2rL3ictd+fDlH5jm/djVFNmiHzuWxQFM jN9vPmRf81Y=lgTy -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Updated jbig2dec packages fix security vulnerability: jbig2_image_compose in jbig2_image.c in Artifex jbig2dec before 0.18 has a heap-based buffer overflow (CVE-2020-12268). . MGASA-2020-0213 - Updated jbig2dec packages fix security vulnerability Publication date: 15 May 2020 URL: https://advisories.mageia.org/MGASA-2020-0213.html Type: security Affected Mageia releases: 7 CVE: CVE-2020-12268 Updated jbig2dec packages fix security vulnerability: jbig2_image_compose in jbig2_image.c in Artifex jbig2dec before 0.18 has a heap-based buffer overflow (CVE-2020-12268). References: - https://bugs.mageia.org/show_bug.cgi?id=26601 - http://lists.suse.com/pipermail/sle-security-updates/2020-May/006802.html - https://www.cve.org/CVERecord?id=CVE-2020-12268 SRPMS: - 7/core/jbig2dec-0.18-1.mga7 . The revised jbig2dec packages resolve a significant buffer overflow vulnerability in Mageia, posing a risk to system integrity.. Mageia Security, jbig2dec Patch, Heap Overflow Fix, Updated Vulnerability. . Severity: Important. LinuxSecurity.com Team
rebase to 0.16 (bz #1741605). --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-55973f4ef8 2019-09-16 02:20:42.426776 --------------------------------------------------------------------------------Name : jbig2dec Product : Fedora 29 Version : 0.16 Release : 1.fc29 URL : https://sourceforge.net/projects/jbig2dec/ Summary : A decoder implementation of the JBIG2 image compression format Description : jbig2dec is a decoder implementation of the JBIG2 image compression format. JBIG2 is designed for lossy or lossless encoding of 'bilevel' (1-bit monochrome) images at moderately high resolution, and in particular scanned paper documents. In this domain it is very efficient, offering compression ratios on the order of 100:1. --------------------------------------------------------------------------------Update Information: rebase to 0.16 (bz #1741605) --------------------------------------------------------------------------------ChangeLog: * Thu Aug 15 2019 Michael J Gruber - 0.16-1 - rebase to 0.16 (bz #1741605) * Thu Jul 25 2019 Fedora Release Engineering - 0.14-6 - Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild * Fri Feb 1 2019 Fedora Release Engineering - 0.14-5 - Rebuilt for https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild * Tue Sep 18 2018 Owen Taylor - 0.14-4 - Handle both compressed and uncompressed man pages --------------------------------------------------------------------------------References: [ 1 ] Bug #1741605 - jbig2dec needs to be rebased to 0.16 (currently 0.14) for ghostscript rebase to 9.27 https://bugzilla.redhat.com/show_bug.cgi?id=1741605 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-55973f4ef8' at the command line. For more information, refer to the dnf documentationavailable at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.