Description
A flaw was found in the opj2_decompress program in openjpeg2 2.4.0 in the way it handles an input directory with a large number of files. When it fails to allocate a buffer to store the filenames of the input directory, it calls free() on an uninitialized pointer, leading to a segmentation fault and a denial of service.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2975-1 | openjpeg2 security update |
Debian DLA |
DLA-4107-1 | openjpeg2 security update |
EUVD |
EUVD-2022-24465 | A flaw was found in the opj2_decompress program in openjpeg2 2.4.0 in the way it handles an input directory with a large number of files. When it fails to allocate a buffer to store the filenames of the input directory, it calls free() on an uninitialized pointer, leading to a segmentation fault and a denial of service. |
Ubuntu USN |
USN-7083-1 | OpenJPEG vulnerabilities |
References
History
Mon, 03 Nov 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2025-11-03T19:26:42.585Z
Reserved: 2022-03-28T00:00:00.000Z
Link: CVE-2022-1122
No data.
Status : Modified
Published: 2022-03-29T18:15:07.977
Modified: 2025-11-03T20:15:52.347
Link: CVE-2022-1122
OpenCVE Enrichment
No data.
Debian DLA
EUVD
Ubuntu USN