PT-2026-92028 · Unknown+2 · Ghostscript+2

·

CVE-2026-39919

·

Published

2026-09-15

·

Updated

2026-10-02

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ghostscript versions prior to 10.08.0
Description A heap-based buffer overflow exists in the JPEG 2000 output adapter within the base/sjpx openjpeg.c file. The issue occurs when processing a crafted PDF containing a JPEG 2000 image with mismatched component subsampling factors. In such cases, the non-samescale sub-byte-depth output path allocates a row buffer sized for packed output but writes a full byte per output column regardless of bit depth. This results in memory corruption of internal chunk-allocator metadata, which can lead to a process crash or remote code execution.
Recommendations Update to version 10.08.0.

Exploit

Fix

RCE

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:74457
ALSA-2026:74464
CVE-2026-39919
ECHO-99AA-3B52-A804
OPENSUSE-SU-2026:11959-1
USN-8791-1

Affected Products

Ghostscript
Linuxmint
Ubuntu