CVE-2025-54874
published 2025-08-05CVE-2025-54874: OpenJPEG is an open-source JPEG 2000 codec. In OpenJPEG from 2.5.1 through 2.5.3, a call to opj_jp2_read_header may lead to OOB heap memory write when the data…
PriorityP345critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.64%
46.7th percentile
OpenJPEG is an open-source JPEG 2000 codec. In OpenJPEG from 2.5.1 through 2.5.3, a call to opj_jp2_read_header may lead to OOB heap memory write when the data stream p_stream is too short and p_image is not initialized.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | openjpeg2 | < openjpeg2 2.5.3-2.1 (forky) | openjpeg2 2.5.3-2.1 (forky) |
| the_openjpeg_project | openjpeg2 | >= 0 < 2.5.3-2.1~deb13u1 | 2.5.3-2.1~deb13u1 |
| the_openjpeg_project | openjpeg2 | >= 0 < 2.5.3-2.1 | 2.5.3-2.1 |
| the_openjpeg_project | openjpeg2 | >= 0 < 2.4.0-6ubuntu0.4 | 2.4.0-6ubuntu0.4 |
| the_openjpeg_project | openjpeg2 | >= 0 < 2.5.0-2ubuntu0.4 | 2.5.0-2ubuntu0.4 |
| the_openjpeg_project | openjpeg2 | >= 0 < 2.3.0-2+deb10u2ubuntu0.1~esm5 | 2.3.0-2+deb10u2ubuntu0.1~esm5 |
| the_openjpeg_project | openjpeg2 | >= 0 < 2.3.1-1ubuntu4.20.04.4+esm1 | 2.3.1-1ubuntu4.20.04.4+esm1 |
| uclouvain | openjpeg | <= 2.5.3 | — |
| uclouvain | openjpeg | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.06.6MEDIUMCVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
osv6.6MEDIUM
vendor_debian6.6LOW
vendor_redhat6.6MEDIUM
vendor_ubuntu6.5MEDIUM
vendor_oracle2.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Database Server Risk Matrix: Oracle Spatial and Graph (OpenJPEG) — CVE-2025-54874
vendor_oracle·2026-01-15·CVSS 2.8
CVE-2025-54874 [MEDIUM] Oracle Oracle Database Server Risk Matrix: Oracle Spatial and Graph (OpenJPEG) — CVE-2025-54874
Oracle Oracle Database Server Risk Matrix: Oracle Spatial and Graph (OpenJPEG) vulnerability
CVE: CVE-2025-54874
CVSS: 2.8
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpujan2026 (JAN 2026)
Ubuntu
OpenJPEG vulnerabilities
vendor_ubuntu·2025-09-18·CVSS 6.5
CVE-2025-54874 [MEDIUM] OpenJPEG vulnerabilities
Title: OpenJPEG vulnerabilities
Summary: Several security issues were fixed in OpenJPEG.
It was discovered that OpenJPEG did not properly handle memory when
decompressing certain image files. An attacker could possibly use this
issue to cause OpenJPEG to crash, resulting in a denial of service. This
issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS,
and Ubuntu 24.04 LTS. (CVE-2025-50952)
It was discovered that OpenJPEG did not properly handle memory when parsing
the headers of certain image files. An attacker could use this issue to
cause OpenJPEG to crash, resulting in a denial of service, or possibly
execute arbitrary code. This issue only affected Ubuntu 25.04.
(CVE-2025-54874)
Instructions: In general, a standard system update will make all the necessary chan
Red Hat
openjpeg: OpenJPEG OOB heap memory write
vendor_redhat·2025-08-05·CVSS 6.6
CVE-2025-54874 [MEDIUM] CWE-457 openjpeg: OpenJPEG OOB heap memory write
openjpeg: OpenJPEG OOB heap memory write
OpenJPEG is an open-source JPEG 2000 codec. In OpenJPEG from 2.5.1 through 2.5.3, a call to opj_jp2_read_header may lead to OOB heap memory write when the data stream p_stream is too short and p_image is not initialized.
An out-of-bounds heap memory write (OOB) flaw was found in OpenJPEG. A call to opj_jp2_read_header may lead to an OOB heap memory write when the data stream p_stream is too short and p_image is not initialized.
Statement: This vulnerability is Important rather than Moderate because it allows a malformed or truncated data stream to trigger a heap-based out-of-bounds (OOB) write, which directly corrupts memory. Unlike read-based issues or null dereference crashes that typically lead to denial of service, an OOB write has the potent
Debian
CVE-2025-54874: openjpeg2 - OpenJPEG is an open-source JPEG 2000 codec. In OpenJPEG from 2.5.1 through 2.5.3...
vendor_debian·2025·CVSS 6.6
CVE-2025-54874 [MEDIUM] CVE-2025-54874: openjpeg2 - OpenJPEG is an open-source JPEG 2000 codec. In OpenJPEG from 2.5.1 through 2.5.3...
OpenJPEG is an open-source JPEG 2000 codec. In OpenJPEG from 2.5.1 through 2.5.3, a call to opj_jp2_read_header may lead to OOB heap memory write when the data stream p_stream is too short and p_image is not initialized.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 2.5.3-2.1)
sid: resolved (fixed in 2.5.3-2.1)
trixie: resolved (fixed in 2.5.3-2.1~deb13u1)
OSV
openjpeg2 vulnerabilities
osv·2025-09-18·CVSS 6.5
CVE-2025-50952 [MEDIUM] openjpeg2 vulnerabilities
openjpeg2 vulnerabilities
It was discovered that OpenJPEG did not properly handle memory when
decompressing certain image files. An attacker could possibly use this
issue to cause OpenJPEG to crash, resulting in a denial of service. This
issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS,
and Ubuntu 24.04 LTS. (CVE-2025-50952)
It was discovered that OpenJPEG did not properly handle memory when parsing
the headers of certain image files. An attacker could use this issue to
cause OpenJPEG to crash, resulting in a denial of service, or possibly
execute arbitrary code. This issue only affected Ubuntu 25.04.
(CVE-2025-54874)
OSV
CVE-2025-54874: OpenJPEG is an open-source JPEG 2000 codec
osv·2025-08-05·CVSS 6.6
CVE-2025-54874 [MEDIUM] CVE-2025-54874: OpenJPEG is an open-source JPEG 2000 codec
OpenJPEG is an open-source JPEG 2000 codec. In OpenJPEG from 2.5.1 through 2.5.3, a call to opj_jp2_read_header may lead to OOB heap memory write when the data stream p_stream is too short and p_image is not initialized.
No detection rules found.
No public exploits indexed.
2025-08-05
Published