Heap-based buffer overflow in OpenJPEG - CVE-2025-54874

 

Heap-based buffer overflow in OpenJPEG - CVE-2025-54874

Published: August 11, 2025 / Updated: February 3, 2026


Vulnerability identifier: #VU113802
CSH Severity: High
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-54874
CWE-ID: CWE-122
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error within the opj_jp2_read_header() function in src/lib/openjp2/jp2.c. A remote attacker can pass specially crafted image to the application, trigger a heap-based buffer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

OpenJPEG
IBM Enterprise Content Management Text Search
Oracle Outside In Technology
Ubuntu
Anolis OS
Fedora
Oracle Solaris
Oracle AutoVue Office
Oracle Database Server
openjpeg2 (Ubuntu package)
openjpeg2 (Red Hat package)
openjpeg2
openjpeg2-devel
openjpeg2-tools
openjpeg2-doc
openjpeg

How to mitigate CVE-2025-54874

Install updates from vendor's website.

IBM Enterprise Content Management Text Search - addressed in versions 5.5.12.0 IF007, 5.6.0.0 IF007, 5.7.0.0 IF004
openjpeg2 (Ubuntu package) - addressed in versions 2.3.0-2+deb10u2ubuntu0.1~esm5, 2.3.1-1ubuntu4.20.04.4+esm1, 2.4.0-6ubuntu0.4, 2.5.0-2ubuntu0.4, 2.5.3-2ubuntu0.1
openjpeg2 (Red Hat package) - update to 2.5.2-4.el10_0.1
openjpeg2 - update to 2.5.3-2
openjpeg2-devel - update to 2.5.3-2
openjpeg2-tools - update to 2.5.3-2
openjpeg2-doc - update to 2.5.3-2
openjpeg - addressed in versions 2.5.3-8.fc41, 2.5.3-8.fc42
Oracle Solaris - update to 11.4 SRU 86

External References

Related Security Bulletins