Heap-based out-of-bounds write in j2k_precinct_subband::parse_packet_header() in OpenHTJ2K versions 0.18.3 and earlier (fixed in v0.18.4) caused by missing bounds validation before coding-pass lengths are written to j2k_codeblock::pass_length[128]. A crafted JPEG 2000 codestream containing malformed PPM packet headers can trigger a heap-based out-of-bounds write in j2k_precinct_subband::parse_packet_header() in source/core/coding/coding_units.cpp due to missing bounds validation for the j2k_codeblock::pass_length[128] array which can lead to heap corruption and process termination.
History

Sat, 01 Aug 2026 10:30:00 +0000

Type Values Removed Values Added
Title Heap-Based Out-of-Bounds Write in OpenHTJ2K Causing Process Termination

Tue, 28 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Heap-Based Out-of-Bounds Write in OpenHTJ2K Causing Process Termination

Sun, 26 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Title Heap-based Out-of-Bounds Write in OpenHTJ2K Leading to Process Termination

Thu, 23 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
Title Heap-based Out-of-Bounds Write in OpenHTJ2K Leading to Process Termination

Fri, 17 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Title Buffer Overflow in OpenHTJ2K’s JPEG 2000 Precinct Subband Parsing Allows Arbitrary Code Execution

Fri, 17 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Description Buffer Overflow vulnerability in OpenHTJ2K v.0.18.4 and before allows an attacker to execute arbitrary code via the j2k_precinct_subband::parse_packet_header() in source/core/coding/coding_units.cpp Heap-based out-of-bounds write in j2k_precinct_subband::parse_packet_header() in OpenHTJ2K versions 0.18.3 and earlier (fixed in v0.18.4) caused by missing bounds validation before coding-pass lengths are written to j2k_codeblock::pass_length[128]. A crafted JPEG 2000 codestream containing malformed PPM packet headers can trigger a heap-based out-of-bounds write in j2k_precinct_subband::parse_packet_header() in source/core/coding/coding_units.cpp due to missing bounds validation for the j2k_codeblock::pass_length[128] array which can lead to heap corruption and process termination.
References

Thu, 16 Jul 2026 08:15:00 +0000

Type Values Removed Values Added
Title Buffer Overflow in OpenHTJ2K’s JPEG 2000 Precinct Subband Parsing Allows Arbitrary Code Execution

Wed, 15 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-121
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Description Buffer Overflow vulnerability in OpenHTJ2K v.0.18.4 and before allows an attacker to execute arbitrary code via the j2k_precinct_subband::parse_packet_header() in source/core/coding/coding_units.cpp
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2026-07-14T00:00:00.000Z

Updated: 2026-07-17T15:02:40.362Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-51807

cve-icon Vulnrichment

Updated: 2026-07-15T14:08:07.304Z

cve-icon NVD

Status : Deferred

Published: 2026-07-14T23:17:29.843

Modified: 2026-07-17T16:17:15.513

Link: CVE-2026-51807

cve-icon Redhat

No data.