mirror of
https://gitlab.com/buildroot.org/buildroot.git
synced 2026-08-01 21:23:51 -09:00
- CVE-2026-6192:
A vulnerability was identified in uclouvain openjpeg up to 2.5.4. This
impacts the function opj_pi_initialise_encode in the library
src/lib/openjp2/pi.c. The manipulation leads to integer overflow. The
attack must be carried out locally. The exploit is publicly available
and might be used. The identifier of the patch is
839936aa33eb8899bbbd80fda02796bb65068951. It is suggested to install a
patch to address this issue.
For more information, see:
- https://www.cve.org/CVERecord?id=CVE-2026-6192
- 839936aa33
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
Signed-off-by: Fiona Klute <fiona.klute@gmx.de>
36 lines
1.4 KiB
Diff
36 lines
1.4 KiB
Diff
From 839936aa33eb8899bbbd80fda02796bb65068951 Mon Sep 17 00:00:00 2001
|
|
From: Even Rouault <even.rouault@spatialys.com>
|
|
Date: Sun, 5 Apr 2026 13:25:27 +0200
|
|
Subject: [PATCH] opj_pi_initialise_encode() (write code path): avoid potential
|
|
integer overflow leading to insufficient memory allocation
|
|
|
|
Fixes #1619
|
|
|
|
CVE: CVE-2026-6192
|
|
Upstream: https://github.com/uclouvain/openjpeg/commit/839936aa33eb8899bbbd80fda02796bb65068951
|
|
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
|
|
---
|
|
src/lib/openjp2/pi.c | 9 ++++++---
|
|
1 file changed, 6 insertions(+), 3 deletions(-)
|
|
|
|
diff --git a/src/lib/openjp2/pi.c b/src/lib/openjp2/pi.c
|
|
index 15ac33142..4abb87af2 100644
|
|
--- a/src/lib/openjp2/pi.c
|
|
+++ b/src/lib/openjp2/pi.c
|
|
@@ -1694,9 +1694,12 @@ opj_pi_iterator_t *opj_pi_initialise_encode(const opj_image_t *p_image,
|
|
l_current_pi = l_pi;
|
|
|
|
/* memory allocation for include*/
|
|
- l_current_pi->include_size = l_tcp->numlayers * l_step_l;
|
|
- l_current_pi->include = (OPJ_INT16*) opj_calloc(l_current_pi->include_size,
|
|
- sizeof(OPJ_INT16));
|
|
+ l_current_pi->include = NULL;
|
|
+ if (l_step_l <= UINT_MAX / l_tcp->numlayers) {
|
|
+ l_current_pi->include_size = l_tcp->numlayers * l_step_l;
|
|
+ l_current_pi->include = (OPJ_INT16*) opj_calloc(l_current_pi->include_size,
|
|
+ sizeof(OPJ_INT16));
|
|
+ }
|
|
if (!l_current_pi->include) {
|
|
opj_free(l_tmp_data);
|
|
opj_free(l_tmp_ptr);
|