#22175 closed enhancement (fixed)
openjpeg-2.5.4
| Reported by: | Douglas R. Reno | Owned by: | Douglas R. Reno |
|---|---|---|---|
| Priority: | high | Milestone: | 13.0 |
| Component: | BOOK | Version: | git |
| Severity: | medium | Keywords: | |
| Cc: |
Description
New point version
Change History (6)
comment:1 by , 13 months ago
| Priority: | normal → elevated |
|---|
comment:2 by , 13 months ago
Changes
OpenJPEG 2.5.4 (Sept 2025)
No API/ABI break compared to v2.5.3
Bug fixes
- opj_jp2_read_header: Check for error after parsing header (CVE-2025-54874)
- pkgconfig: drop unused libraries from Libs.private
- Fix CMake warning: Compatibility with CMake < 3.10 will be removed
- Fixed ICC profile copy failure on write
comment:3 by , 13 months ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
comment:4 by , 12 months ago
| Priority: | elevated → high |
|---|
https://nvd.nist.gov/vuln/detail/CVE-2025-54874 denotes this 9.8/10 CRITICAL.
comment:5 by , 12 months ago
| Resolution: | → fixed |
|---|---|
| Status: | assigned → closed |
Fixed at c7d90d8f0acc7c50ec2d8d2a42d19499731bce27
SA-12.4-009 issued
Note:
See TracTickets
for help on using tickets.

Fixes CVE-2025-54874, which allows an attacker to write to heap memory via an out of bounds vulnerability, rated as Medium.