OpenJPEG: two distinct heap buffer overflows — encoder-side DWT bug in 2.4.0–2.5.4, plus unreleased fix for heap write in opj_j2k_read_sod()
Two separate heap buffer overflows affect OpenJPEG: an encoder-side overflow in the reversible 5/3 wavelet transform (opj_dwt_encode_and_deinterleave_v()) spanning versions 2.4.0 through 2.5.4 and git master, and a heap-buffer-overflow write in…
OpenJPEG is contending with two distinct heap buffer overflows disclosed on oss-security in October 2026. On 2026-10-05, Red Eagle Tech reported a heap buffer overflow in opj_dwt_encode_and_deinterleave_v(), the reversible 5/3 forward discrete wavelet transform, affecting OpenJPEG 2.4.0 through 2.5.4 and git master. The bug is encoder-side: it is reached through encoding parameters rather than a crafted input file, and triggers when a tile's lower resolution levels have zero height at an odd start. A single encode may appear fine while repeating the same encode in one process can expose the flaw. On 2026-10-08, a second issue was reported: a heap-buffer-overflow write in opj_j2k_read_sod() in src/lib/openjp2/j2k.c, which was fixed on master on 2026-02-10 but has never shipped in a release — both v2.5.3 and v2.5.4 contain the vulnerable code, and distributions are packaging those releases. The reports do not disagree; they describe different bugs in different code paths. Notably, no CVE or advisory is mapped to the j2k.c flaw for distro packages, making it unlikely to be on packagers' radars, and neither report assigns a CVE to its respective bug.
- Bug 1: heap buffer overflow in opj_dwt_encode_and_deinterleave_v() (reversible 5/3 forward DWT), encoder-side
- Bug 1 affects OpenJPEG 2.4.0 through 2.5.4 and git master
- Bug 1 was reported by Red Eagle Tech
- Bug 1 is triggered via encoding parameters — not a crafted input file — when a tile's lower resolution levels have zero height at an odd start
- Bug 1 may not surface on a single encode; repeating the same encode in one process can expose it
- Bug 2: heap-buffer-overflow WRITE in opj_j2k_read_sod() in src/lib/openjp2/j2k.c
- Bug 2 was fixed on master on 2026-02-10 but the fix is absent from every release, including v2.5.3 and v2.5.4
- Distributions are shipping the releases containing the vulnerable j2k.c code
Coverage timelineoldest first · each row is one article
- · 3d agoopenjpeg 2.4.0 through 2.5.4 and git master: heap buffer overflow in opj_dwt_encode_and_deinterleave_v() (reversible 5/3 forward DWT, encoder)
oss-security· 52
OpenJPEG 2.4.0 through 2.5.4 has an encoder-side heap overflow in its reversible 5/3 wavelet transform.
- · 14h agoOpenJPEG: heap-buffer-overflow write fixed on master since Feb 2026, still present in every release (2.5.3, 2.5.4)
oss-security· 42
OpenJPEG heap-buffer-overflow write fixed on master in February 2026 still ships in releases 2.5.3 and 2.5.4, with no CVE or advisory.