CVE-2025-50952
published 2025-08-07CVE-2025-50952: openjpeg v 2.5.0 was discovered to contain a NULL pointer dereference via the component /openjp2/dwt.c.
PriorityP431medium6.5CVSS 3.1
AVNACLPRNUINSUCLILAN
EPSS
0.26%
17.7th percentile
openjpeg v 2.5.0 was discovered to contain a NULL pointer dereference via the component /openjp2/dwt.c.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | openjpeg2 | < openjpeg2 2.5.0-2+deb12u2 (bookworm) | openjpeg2 2.5.0-2+deb12u2 (bookworm) |
| the_openjpeg_project | openjpeg2 | >= 0 < 2.4.0-3+deb11u2 | 2.4.0-3+deb11u2 |
| the_openjpeg_project | openjpeg2 | >= 0 < 2.5.0-2+deb12u2 | 2.5.0-2+deb12u2 |
| the_openjpeg_project | openjpeg2 | >= 0 < 2.5.3-1 | 2.5.3-1 |
| the_openjpeg_project | openjpeg2 | >= 0 < 2.5.3-1 | 2.5.3-1 |
| the_openjpeg_project | openjpeg2 | >= 0 < 2.4.0-6ubuntu0.4 | 2.4.0-6ubuntu0.4 |
| the_openjpeg_project | openjpeg2 | >= 0 < 2.5.0-2ubuntu0.4 | 2.5.0-2ubuntu0.4 |
| the_openjpeg_project | openjpeg2 | >= 0 < 2.3.0-2+deb10u2ubuntu0.1~esm5 | 2.3.0-2+deb10u2ubuntu0.1~esm5 |
| the_openjpeg_project | openjpeg2 | >= 0 < 2.3.1-1ubuntu4.20.04.4+esm1 | 2.3.1-1ubuntu4.20.04.4+esm1 |
| uclouvain | openjpeg | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
OpenJPEG vulnerabilities
vendor_ubuntu·2025-09-18·CVSS 6.5
CVE-2025-54874 [MEDIUM] OpenJPEG vulnerabilities
Title: OpenJPEG vulnerabilities
Summary: Several security issues were fixed in OpenJPEG.
It was discovered that OpenJPEG did not properly handle memory when
decompressing certain image files. An attacker could possibly use this
issue to cause OpenJPEG to crash, resulting in a denial of service. This
issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS,
and Ubuntu 24.04 LTS. (CVE-2025-50952)
It was discovered that OpenJPEG did not properly handle memory when parsing
the headers of certain image files. An attacker could use this issue to
cause OpenJPEG to crash, resulting in a denial of service, or possibly
execute arbitrary code. This issue only affected Ubuntu 25.04.
(CVE-2025-54874)
Instructions: In general, a standard system update will make all the necessary chan
Red Hat
openjpeg: Openjpeg NULL pointer dereference
vendor_redhat·2025-08-07·CVSS 6.5
CVE-2025-50952 [MEDIUM] CWE-476 openjpeg: Openjpeg NULL pointer dereference
openjpeg: Openjpeg NULL pointer dereference
openjpeg v 2.5.0 was discovered to contain a NULL pointer dereference via the component /openjp2/dwt.c.
A null pointer dereference vulnerability has been discovered in the openjpeg library. This flaw, identified through a fuzzing tool, could allow an attacker to cause a crash in an application processing a specially crafted file. While no active exploit has been demonstrated, a successful attack would lead to a denial-of-service condition. This presents a risk to the availability of systems that utilize openjpeg to process untrusted input.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to wide
Debian
CVE-2025-50952: openjpeg2 - openjpeg v 2.5.0 was discovered to contain a NULL pointer dereference via the co...
vendor_debian·2025·CVSS 6.5
CVE-2025-50952 [MEDIUM] CVE-2025-50952: openjpeg2 - openjpeg v 2.5.0 was discovered to contain a NULL pointer dereference via the co...
openjpeg v 2.5.0 was discovered to contain a NULL pointer dereference via the component /openjp2/dwt.c.
Scope: local
bookworm: resolved (fixed in 2.5.0-2+deb12u2)
bullseye: resolved (fixed in 2.4.0-3+deb11u2)
forky: resolved (fixed in 2.5.3-1)
sid: resolved (fixed in 2.5.3-1)
trixie: resolved (fixed in 2.5.3-1)
OSV
openjpeg2 vulnerabilities
osv·2025-09-18·CVSS 6.5
CVE-2025-50952 [MEDIUM] openjpeg2 vulnerabilities
openjpeg2 vulnerabilities
It was discovered that OpenJPEG did not properly handle memory when
decompressing certain image files. An attacker could possibly use this
issue to cause OpenJPEG to crash, resulting in a denial of service. This
issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS,
and Ubuntu 24.04 LTS. (CVE-2025-50952)
It was discovered that OpenJPEG did not properly handle memory when parsing
the headers of certain image files. An attacker could use this issue to
cause OpenJPEG to crash, resulting in a denial of service, or possibly
execute arbitrary code. This issue only affected Ubuntu 25.04.
(CVE-2025-54874)
OSV
CVE-2025-50952: openjpeg v 2
osv·2025-08-07·CVSS 6.5
CVE-2025-50952 [MEDIUM] CVE-2025-50952: openjpeg v 2
openjpeg v 2.5.0 was discovered to contain a NULL pointer dereference via the component /openjp2/dwt.c.
GHSA
GHSA-2pr5-qxg3-pfqf: openjpeg v 2
ghsa_unreviewed·2025-08-07
CVE-2025-50952 [MEDIUM] CWE-476 GHSA-2pr5-qxg3-pfqf: openjpeg v 2
openjpeg v 2.5.0 was discovered to contain a NULL pointer dereference via the component /openjp2/dwt.c.
No detection rules found.
No public exploits indexed.
2025-08-07
Published