OpenJPEG: heap-buffer-overflow write fixed on master since Feb 2026, still present in every release (2.5.3, 2.5.4)
OpenJPEG heap-buffer-overflow write fixed on master in February 2026 still ships in releases 2.5.3 and 2.5.4, with no CVE or advisory.
A heap-buffer-overflow write in OpenJPEG's src/lib/openjp2/j2k.c, in opj_j2k_read_sod(), was fixed on master on 2026-02-10 but has never appeared in a release. Both v2.5.3 and v2.5.4 contain the vulnerable code, and distributions are shipping them. No CVE or advisory is mapped to distro packages, so the flaw is unlikely to be on packagers' radars.
- Heap-buffer-overflow WRITE in opj_j2k_read_sod() in OpenJPEG's j2k.c.
- Fixed on master 2026-02-10 but missing from releases 2.5.3 and 2.5.4.
- No CVE or distro advisory exists, leaving packagers likely unaware.
Posted by TheSecguy on Oct 08 Hello, Short version: OpenJPEG has had a heap-buffer-overflow WRITE fixed on master since 2026-02-10 that has never appeared in a release. Every released version containing the affected code -- v2.5.3 and v2.5.4 -- is still vulnerable, and distributions are shipping it. There is no CVE and no advisory mapped to distro packages, so it is unlikely to be on packagers' radars. THE DEFECT src/lib/openjp2/j2k.c, in opj_j2k_read_sod():...
This source does not provide full text. Read it at seclists.org.