CVE-2025-54874

OpenJPEG is an open-source JPEG 2000 codec. In OpenJPEG 2.5.3 and earlier, a call to opj_jp2_read_header may lead to OOB heap memory write when the data stream p_stream is too short and p_image is not initialized.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
UNKNOWN
---
GitHub_MCNA
---
---
CISA-ADPADP
---
---
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Debian logo
Debian Releases
Debian Product
Codename
openjpeg2
bullseye
2.4.0-3
not-affected
bookworm
2.5.0-2+deb12u1
not-affected
bullseye (security)
2.4.0-3+deb11u1
fixed
bookworm (security)
2.5.0-2+deb12u1
fixed
sid
vulnerable
trixie
vulnerable