CVE-2026-6192
published 2026-04-13CVE-2026-6192: A vulnerability was identified in uclouvain openjpeg up to 2.5.4. This impacts the function opj_pi_initialise_encode in the library src/lib/openjp2/pi.c. The…
PriorityP411low3.3CVSS 3.1
AVLACLPRLUINSUCNINAL
EPSS
0.11%
1.6th percentile
A vulnerability was identified in uclouvain openjpeg up to 2.5.4. This impacts the function opj_pi_initialise_encode in the library src/lib/openjp2/pi.c. The manipulation leads to integer overflow. The attack must be carried out locally. The exploit is publicly available and might be used. The identifier of the patch is 839936aa33eb8899bbbd80fda02796bb65068951. It is suggested to install a patch to address this issue.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ubuntu | openjpeg2 | — | — |
| uclouvain | openjpeg | — | — |
| uclouvain | openjpeg | — | — |
| uclouvain | openjpeg | — | — |
| uclouvain | openjpeg | — | — |
| uclouvain | openjpeg | — | — |
CVSS provenance
nvdv3.13.3LOWCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
nvdv4.01.9LOWCVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.01.7LOWAV:L/AC:L/Au:S/C:N/I:N/A:P
vendor_redhat4.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
OpenJPEG vulnerability
vendor_ubuntu·2026-05-07
CVE-2026-6192 OpenJPEG vulnerability
Title: OpenJPEG vulnerability
Summary: OpenJPEG could be made to crash or run programs when encoding image files.
It was discovered that OpenJPEG did not properly handle memory when
encoding image files. An attacker could use this issue to cause OpenJPEG to
crash, resulting in a denial of service, or possibly execute arbitrary
code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
uclouvain/openjpeg: OpenJPEG: Denial of Service via integer overflow in opj_pi_initialise_encode
vendor_redhat·2026-04-13·CVSS 4.8
CVE-2026-6192 [MEDIUM] CWE-190 uclouvain/openjpeg: OpenJPEG: Denial of Service via integer overflow in opj_pi_initialise_encode
uclouvain/openjpeg: OpenJPEG: Denial of Service via integer overflow in opj_pi_initialise_encode
A vulnerability was identified in uclouvain openjpeg up to 2.5.4. This impacts the function opj_pi_initialise_encode in the library src/lib/openjp2/pi.c. The manipulation leads to integer overflow. The attack must be carried out locally. The exploit is publicly available and might be used. The identifier of the patch is 839936aa33eb8899bbbd80fda02796bb65068951. It is suggested to install a patch to address this issue.
A flaw was found in uclouvain openjpeg. A local attacker can exploit an integer overflow vulnerability within the `opj_pi_initialise_encode` function. This manipulation can lead to a Denial of Service (DoS), making the affected system or application unavailable.
Package: openjp
VulDB
uclouvain openjpeg up to 2.5.4 src/lib/openjp2/pi.c opj_pi_initialise_encode integer overflow (Issue 1619 / Nessus ID 314995)
vuldb·2026-05-21·CVSS 1.9
CVE-2026-6192 [LOW] uclouvain openjpeg up to 2.5.4 src/lib/openjp2/pi.c opj_pi_initialise_encode integer overflow (Issue 1619 / Nessus ID 314995)
A vulnerability, which was classified as problematic, has been found in uclouvain openjpeg up to 2.5.4. This impacts the function opj_pi_initialise_encode in the library src/lib/openjp2/pi.c. The manipulation leads to integer overflow.
This vulnerability is listed as CVE-2026-6192. The attack must be carried out locally. In addition, an exploit is available.
It is suggested to install a patch to address this issue.
GHSA
GHSA-6jfp-5ggc-pgmx: A vulnerability was identified in uclouvain openjpeg up to 2
ghsa_unreviewed·2026-04-13
CVE-2026-6192 [MEDIUM] GHSA-6jfp-5ggc-pgmx: A vulnerability was identified in uclouvain openjpeg up to 2
A vulnerability was identified in uclouvain openjpeg up to 2.5.4. This impacts the function opj_pi_initialise_encode in the library src/lib/openjp2/pi.c. The manipulation leads to integer overflow. The attack must be carried out locally. The exploit is publicly available and might be used. The identifier of the patch is 839936aa33eb8899bbbd80fda02796bb65068951. It is suggested to install a patch to address this issue.
No detection rules found.
No public exploits indexed.
https://github.com/uclouvain/openjpeg/https://github.com/uclouvain/openjpeg/commit/839936aa33eb8899bbbd80fda02796bb65068951https://github.com/uclouvain/openjpeg/issues/1619https://github.com/uclouvain/openjpeg/pull/1628https://vuldb.com/submit/797385https://vuldb.com/vuln/357114https://vuldb.com/vuln/357114/ctihttps://lists.debian.org/debian-lts-announce/2026/05/msg00038.html
2026-04-13
Published