freenode
Security & Cryptography

OpenJPEG leaves heap overflow in all releases as project goes idle

A February 2026 fix never shipped; 2.5.3 and 2.5.4 remain vulnerable in distros and PDF toolchains, with no CVE.

OpenJPEG still ships a heap buffer overflow write in every current release, even though a fix has sat on the development tree since February 2026. Versions 2.5.3 and 2.5.4 remain vulnerable, distributions continue to package them, and no CVE or vendor advisory has been issued to put the flaw on packagers' radars.

The defect was introduced in mid-2024 by a tile-part indexing optimisation. A one-byte field taken from the codestream can walk past a heap allocation and write values derived from attacker-controlled length data, reaching several kilobytes beyond the buffer. Releases through 2.5.2 are not affected. The path is practical in the wild: a JPEG 2000 image embedded in a PDF is enough, and the overflow has been reproduced under AddressSanitizer via Poppler, MuPDF, Ghostscript, and ImageMagick.

The bug was catalogued as OSV-2025-219 after an OSS-Fuzz report and repaired on master in February 2026. That repair never appeared in a tagged release. The newest tag is still 2.5.4, from September 2025.

The project has since declared itself unmaintained. Its notice states that commits may appear "depending on committer interest and mood," but that no committer currently feels responsible for regularly reviewing tickets or pull requests. Without a release or a CVE, the existing fix is unlikely to reach distribution packages on its own.