An integer overflow in the jbig2_arith_iaid_ctx_new() function of Artifex commit cc37d0 allows attackers to cause a Denial of Service (DoS) via a crafted input.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux_2023 | — | Upgrade jbig2dec-libsUpgrade jbig2dec-debuginfoUpgrade jbig2dec-debugsourceUpgrade jbig2dec-develUpgrade jbig2decUpgrade jbig2dec-libs-debuginfo | Aug 10, 2026 | Jul 9, 2026 |
| Debian | — | Upgrade jbig2dec | Sep 21, 2026 | Jul 9, 2026 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Jul 9, 2026 |
| Ubuntu | — | Upgrade libjbig2dec0Upgrade jbig2decNo solution exists | Jul 22, 2026 | Jul 21, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub