PT-2025-31936 · Openjpeg+3 · Openjpeg+3

·

CVE-2025-54874

·

Published

2025-08-05

·

Updated

2026-08-31

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenJPEG versions 2.5.3 and earlier
Description OpenJPEG is an open-source JPEG 2000 codec. A call to the opj jp2 read header function may lead to an out-of-bounds heap memory write when the data stream p stream is too short and p image is not initialized.
Recommendations Update OpenJPEG to a version later than 2.5.3.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025:13944
ALT-PU-2025-12044
AZL-66090
AZL-66114
BDU:2025-13203
CVE-2025-54874
OPENSUSE-SU-2025:15421-1
OPENSUSE-SU-2025:20076-1
OPENSUSE-SU-2026:20842-1
RHSA-2025:13944
SUSE-SU-2026:21995-1
USN-7757-1

Affected Products

Alt Linux
Linuxmint
Openjpeg
Ubuntu