Back

MEDIUM

openjpeg: segmentation fault in opj2_decompress due to uninitialized pointer

Published Mar 29, 2022

Description

A flaw was found in the opj2_decompress program in openjpeg2 2.4.0 in the way it handles an input directory with a large number of files. When it fails to allocate a buffer to store the filenames of the input directory, it calls free() on an uninitialized pointer, leading to a segmentation fault and a denial of service.

Affected products

Remediation

Red Hat statement

This flaw affects the opj2_compress utility but is not in the openjpeg2 library. Therefore, the attack vector is local to the opj2_compress utility and would require an attacker to convince a user to open a directory with an extremely large number of files using opj2_compress, or a script to be feeding such arbitrary, untrusted files to opj2_compress.

Metrics

Weaknesses (2)

References (11)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Mar 29, 2022
Updated Nov 3, 2025
Reserved Mar 28, 2022
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Jul 13, 2021