Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
OpenJPEG could be made to crash or run programs when encoding image files.. ========================================================================== Ubuntu Security Notice USN-8252-1 May 07, 2026 openjpeg2 vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: OpenJPEG could be made to crash or run programs when encoding image files. Software Description: - openjpeg2: JPEG 2000 image compression/decompression library Details: It was discovered that OpenJPEG did not properly handle memory when encoding image files. An attacker could use this issue to cause OpenJPEG to crash, resulting in a denial of service, or possibly execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS libopenjp2-7 2.5.4-1ubuntu0.1 Ubuntu 25.10 libopenjp2-7 2.5.3-2.1ubuntu0.1 Ubuntu 24.04 LTS libopenjp2-7 2.5.0-2ubuntu0.5 Ubuntu 22.04 LTS libopenjp2-7 2.4.0-6ubuntu0.5 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8252-1 CVE-2026-6192 Package Information: https://launchpad.net/ubuntu/+source/openjpeg2/2.5.4-1ubuntu0.1 https://launchpad.net/ubuntu/+source/openjpeg2/2.5.3-2.1ubuntu0.1 https://launchpad.net/ubuntu/+source/openjpeg2/2.5.0-2ubuntu0.5 https://launchpad.net/ubuntu/+source/openjpeg2/2.4.0-6ubuntu0.5 . OpenJPEG on Ubuntu has a critical memory handling issue allowing DoS or code execution. Update your systems promptly.. Ubuntu Security Notice OpenJPEG memory issue DoS update. . Severity: Important. LinuxSecurity.com Team
* bsc#1227410 * bsc#1250467 Cross-References: * CVE-2023-39327 . # Security update for openjpeg Announcement ID: SUSE-SU-2025:3946-1 Release Date: 2025-11-05T08:17:30Z Rating: moderate References: * bsc#1227410 * bsc#1250467 Cross-References: * CVE-2023-39327 CVSS scores: * CVE-2023-39327 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2023-39327 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L Affected Products: * Desktop Applications Module 15-SP6 * Desktop Applications Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability and has one security fix can now be installed. ## Description: This update for openjpeg fixes the following issues: * CVE-2023-39327: Fixed that malicious files can cause a large loop that continuously prints warning messages on the terminal (bsc#1227410). Other bug fixes: * Ensure no bundled libraries are used (bsc#1250467). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Desktop Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-3946=1 * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2025-3946=1 * Desktop Applications Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP6-2025-3946=1 ## Package List: * Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * openjpeg-debugsource-1.5.2-150000.4.15.1 *openjpeg-debuginfo-1.5.2-150000.4.15.1 * libopenjpeg1-1.5.2-150000.4.15.1 * openjpeg-devel-1.5.2-150000.4.15.1 * libopenjpeg1-debuginfo-1.5.2-150000.4.15.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * openjpeg-debugsource-1.5.2-150000.4.15.1 * openjpeg-debuginfo-1.5.2-150000.4.15.1 * libopenjpeg1-1.5.2-150000.4.15.1 * openjpeg-1.5.2-150000.4.15.1 * openjpeg-devel-1.5.2-150000.4.15.1 * libopenjpeg1-debuginfo-1.5.2-150000.4.15.1 * openSUSE Leap 15.6 (x86_64) * openjpeg-devel-32bit-1.5.2-150000.4.15.1 * libopenjpeg1-32bit-1.5.2-150000.4.15.1 * libopenjpeg1-32bit-debuginfo-1.5.2-150000.4.15.1 * Desktop Applications Module 15-SP6 (aarch64 ppc64le s390x x86_64) * openjpeg-debugsource-1.5.2-150000.4.15.1 * openjpeg-debuginfo-1.5.2-150000.4.15.1 * libopenjpeg1-1.5.2-150000.4.15.1 * openjpeg-devel-1.5.2-150000.4.15.1 * libopenjpeg1-debuginfo-1.5.2-150000.4.15.1 ## References: * https://www.suse.com/security/cve/CVE-2023-39327.html * https://bugzilla.suse.com/show_bug.cgi?id=1227410 * https://bugzilla.suse.com/show_bug.cgi?id=1250467 . This update addresses a moderate security issue in openjpeg, preventing potential denial of service attacks.. openSUSE security, openjpeg update, DoS prevention, Linux security patches. . LinuxSecurity.com Team
An update that solves one vulnerability and has one security fix can now be installed.. # Security update for openjpeg Announcement ID: SUSE-SU-2025:3946-1 Release Date: 2025-11-05T08:17:30Z Rating: moderate References: * bsc#1227410 * bsc#1250467 Cross-References: * CVE-2023-39327 CVSS scores: * CVE-2023-39327 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2023-39327 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L Affected Products: * Desktop Applications Module 15-SP6 * Desktop Applications Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability and has one security fix can now be installed. ## Description: This update for openjpeg fixes the following issues: * CVE-2023-39327: Fixed that malicious files can cause a large loop that continuously prints warning messages on the terminal (bsc#1227410). Other bug fixes: * Ensure no bundled libraries are used (bsc#1250467). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Desktop Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-3946=1 * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2025-3946=1 * Desktop Applications Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP6-2025-3946=1 ## Package List: * Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * openjpeg-debugsource-1.5.2-150000.4.15.1 *openjpeg-debuginfo-1.5.2-150000.4.15.1 * libopenjpeg1-1.5.2-150000.4.15.1 * openjpeg-devel-1.5.2-150000.4.15.1 * libopenjpeg1-debuginfo-1.5.2-150000.4.15.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * openjpeg-debugsource-1.5.2-150000.4.15.1 * openjpeg-debuginfo-1.5.2-150000.4.15.1 * libopenjpeg1-1.5.2-150000.4.15.1 * openjpeg-1.5.2-150000.4.15.1 * openjpeg-devel-1.5.2-150000.4.15.1 * libopenjpeg1-debuginfo-1.5.2-150000.4.15.1 * openSUSE Leap 15.6 (x86_64) * openjpeg-devel-32bit-1.5.2-150000.4.15.1 * libopenjpeg1-32bit-1.5.2-150000.4.15.1 * libopenjpeg1-32bit-debuginfo-1.5.2-150000.4.15.1 * Desktop Applications Module 15-SP6 (aarch64 ppc64le s390x x86_64) * openjpeg-debugsource-1.5.2-150000.4.15.1 * openjpeg-debuginfo-1.5.2-150000.4.15.1 * libopenjpeg1-1.5.2-150000.4.15.1 * openjpeg-devel-1.5.2-150000.4.15.1 * libopenjpeg1-debuginfo-1.5.2-150000.4.15.1 ## References: * https://www.suse.com/security/cve/CVE-2023-39327.html * https://bugzilla.suse.com/show_bug.cgi?id=1227410 * https://bugzilla.suse.com/show_bug.cgi?id=1250467 . This update addresses a moderate risk related to openjpeg, fixing issues allowing denial of service attacks on openSUSE.. SUSE Linux, openjpeg, security update, moderate risk, denial of service. . LinuxSecurity.com Team
Several security issues were fixed in OpenJPEG.. ========================================================================== Ubuntu Security Notice USN-7757-1 September 18, 2025 openjpeg2 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.04 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: Several security issues were fixed in OpenJPEG. Software Description: - openjpeg2: JPEG 2000 image compression/decompression library Details: It was discovered that OpenJPEG did not properly handle memory when decompressing certain image files. An attacker could possibly use this issue to cause OpenJPEG to crash, resulting in a denial of service. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS. (CVE-2025-50952) It was discovered that OpenJPEG did not properly handle memory when parsing the headers of certain image files. An attacker could use this issue to cause OpenJPEG to crash, resulting in a denial of service, or possibly execute arbitrary code. This issue only affected Ubuntu 25.04. (CVE-2025-54874) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.04 libopenjp2-7 2.5.3-2ubuntu0.1 Ubuntu 24.04 LTS libopenjp2-7 2.5.0-2ubuntu0.4 Ubuntu 22.04 LTS libopenjp2-7 2.4.0-6ubuntu0.4 libopenjp3d7 2.4.0-6ubuntu0.4 Ubuntu 20.04 LTS libopenjp2-7 2.3.1-1ubuntu4.20.04.4+esm1 Available with Ubuntu Pro libopenjp3d7 2.3.1-1ubuntu4.20.04.4+esm1 Available with Ubuntu Pro Ubuntu 18.04 LTS libopenjp2-7 2.3.0-2+deb10u2ubuntu0.1~esm5 Available with Ubuntu Pro libopenjp3d7 2.3.0-2+deb10u2ubuntu0.1~esm5 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7757-1 CVE-2025-50952, CVE-2025-54874 Package Information: https://launchpad.net/ubuntu/+source/openjpeg2/2.5.3-2ubuntu0.1 https://launchpad.net/ubuntu/+source/openjpeg2/2.4.0-6ubuntu0.4 . Vulnerabilities discovered in OpenJPEG pose significant security threats; potential for denial of service affecting various Ubuntu releases. Immediate action recommended.. OpenJPEG vulnerabilities, Ubuntu security issues, memory handling errors. . Severity: Important. LinuxSecurity.com Team
Backport fix for CVE-2025-54874.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-4588dcd9ee 2025-08-13 01:31:18.135856+00:00 -------------------------------------------------------------------------------- Name : openjpeg Product : Fedora 41 Version : 2.5.3 Release : 8.fc41 URL : https://github.com/uclouvain/openjpeg Summary : C-Library for JPEG 2000 Description : The OpenJPEG library is an open-source JPEG 2000 library developed in order to promote the use of JPEG 2000. This package contains * JPEG 2000 codec compliant with the Part 1 of the standard (Class-1 Profile-1 compliance). * JP2 (JPEG 2000 standard Part 2 - Handling of JP2 boxes and extended multiple component transforms for multispectral and hyperspectral imagery) -------------------------------------------------------------------------------- Update Information: Backport fix for CVE-2025-54874. -------------------------------------------------------------------------------- ChangeLog: * Sun Aug 10 2025 Sandro Mani - 2.5.3-8 - Backport fix for CVE-2025-54874 * Thu Jul 24 2025 Fedora Release Engineering - 2.5.3-7 - Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2386563 - CVE-2025-54874 openjpeg: OpenJPEG OOB heap memory write [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2386563 [ 2 ] Bug #2386568 - CVE-2025-54874 openjpeg: OpenJPEG OOB heap memory write [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2386568 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-4588dcd9ee' at the command line. For more information, refer to the dnf documentation availableat http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Backport fix for CVE-2025-54874.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-8355fbd790 2025-08-12 00:55:59.003836+00:00 -------------------------------------------------------------------------------- Name : openjpeg Product : Fedora 42 Version : 2.5.3 Release : 8.fc42 URL : https://github.com/uclouvain/openjpeg Summary : C-Library for JPEG 2000 Description : The OpenJPEG library is an open-source JPEG 2000 library developed in order to promote the use of JPEG 2000. This package contains * JPEG 2000 codec compliant with the Part 1 of the standard (Class-1 Profile-1 compliance). * JP2 (JPEG 2000 standard Part 2 - Handling of JP2 boxes and extended multiple component transforms for multispectral and hyperspectral imagery) -------------------------------------------------------------------------------- Update Information: Backport fix for CVE-2025-54874. -------------------------------------------------------------------------------- ChangeLog: * Sun Aug 10 2025 Sandro Mani - 2.5.3-8 - Backport fix for CVE-2025-54874 * Thu Jul 24 2025 Fedora Release Engineering - 2.5.3-7 - Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2386563 - CVE-2025-54874 openjpeg: OpenJPEG OOB heap memory write [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2386563 [ 2 ] Bug #2386568 - CVE-2025-54874 openjpeg: OpenJPEG OOB heap memory write [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2386568 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-8355fbd790' at the command line. For more information, refer to the dnf documentation availableat http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
OpenJPEG could be made to crash if it opened a specially crafted file.. ========================================================================== Ubuntu Security Notice USN-7037-1 September 26, 2024 openjpeg2 vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: OpenJPEG could be made to crash if it opened a specially crafted file. Software Description: - openjpeg2: JPEG 2000 image compression/decompression library Details: It was discovered that OpenJPEG could enter a large loop and continuously print warning messages when given specially crafted input. An attacker could potentially use this issue to cause a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS libopenjp2-7 2.5.0-2ubuntu0.1 libopenjpip7 2.5.0-2ubuntu0.1 Ubuntu 22.04 LTS libopenjp2-7 2.4.0-6ubuntu0.1 libopenjp3d7 2.4.0-6ubuntu0.1 libopenjpip7 2.4.0-6ubuntu0.1 Ubuntu 20.04 LTS libopenjp2-7 2.3.1-1ubuntu4.20.04.2 libopenjp3d7 2.3.1-1ubuntu4.20.04.2 libopenjpip7 2.3.1-1ubuntu4.20.04.2 Ubuntu 18.04 LTS libopenjp2-7 2.3.0-2+deb10u2ubuntu0.1~esm2 Available with Ubuntu Pro libopenjp3d7 2.3.0-2+deb10u2ubuntu0.1~esm2 Available with UbuntuPro libopenjpip7 2.3.0-2+deb10u2ubuntu0.1~esm2 Available with Ubuntu Pro Ubuntu 16.04 LTS libopenjp2-7 2.1.2-1.1+deb9u6ubuntu0.1esm4 Available with Ubuntu Pro libopenjp3d7 2.1.2-1.1+deb9u6ubuntu0.1~esm4 Available with Ubuntu Pro libopenjpip7 2.1.2-1.1+deb9u6ubuntu0.1~esm4 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7037-1 CVE-2023-39327 Package Information: https://launchpad.net/ubuntu/+source/openjpeg2/2.5.0-2ubuntu0.1 https://launchpad.net/ubuntu/+source/openjpeg2/2.4.0-6ubuntu0.1 https://launchpad.net/ubuntu/+source/openjpeg2/2.3.1-1ubuntu4.20.04.2 . The OpenJPEG library on Ubuntu may experience crashes while handling specifically designed files; it is advisable to upgrade your packages to address this denial of service vulnerability.. OpenJPEG, denial of service, Ubuntu updates, software security, system security. . LinuxSecurity.com Team
New openjpeg packages are available for Slackware 15.0 and -current to fix a security issue. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] openjpeg (SSA:2024-057-01) New openjpeg packages are available for Slackware 15.0 and -current to fix a security issue. Here are the details from the Slackware 15.0 ChangeLog: +--------------------------+ patches/packages/openjpeg-2.5.1-i586-1_slack15.0.txz: Upgraded. Fixed a heap-based buffer overflow in openjpeg in color.c:379:42 in sycc420_to_rgb when decompressing a crafted .j2k file. An attacker could use this to execute arbitrary code with the permissions of the application compiled against openjpeg. For more information, see: https://www.cve.org/CVERecord?id=CVE-2021-3575 (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you. Updated package for Slackware 15.0: Updated package for Slackware x86_64 15.0: Updated package for Slackware -current: Updated package for Slackware x86_64 -current: MD5 signatures: +-------------+ Slackware 15.0 package: b48dde1596a6bbd4ff17853d6305f5d9 openjpeg-2.5.1-i586-1_slack15.0.txz Slackware x86_64 15.0 package: 953919aa0e6828dc2edff548e4643a10 openjpeg-2.5.1-x86_64-1_slack15.0.txz Slackware -current package: 6ad0d352dbc55d1b5e3d5ffc0b518d41 l/openjpeg-2.5.1-i586-1.txz Slackware x86_64 -current package: f4db01328ea44fa02c8bc8c31661f795 l/openjpeg-2.5.1-x86_64-1.txz Installation instructions: +------------------------+ Upgrade the package as root: # upgradepkg openjpeg-2.5.1-i586-1_slack15.0.txz +-----+ . Recent updates for openjpeg address a security vulnerability, mitigating the risk of unauthorized code execution on Slackware environments.. Openjpeg Update, SlackwareSecurity, Buffer Overflow Fix, Software Patch, Threat Management. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.