yocto ▾
›
kirkstone ▾
›
vulnerability
›
CVE-2021-29338
Component Overview
Vulnerability Overview
Name
CVE-2021-29338
Source
NVD (
link
)
Debian (
link
)
Description
Integer Overflow in OpenJPEG v2.4.0 allows remote attackers to crash the application, causing a Denial of Service (DoS). This occurs when the attacker uses the command line option "-ImgDir" on a directory that contains 1048576 files.
CWEs
CWE-190
Published Date
Apr 14, 2021
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://github.com/uclouvain/openjpeg/issues/1338
Exploit
https://lists.debian.org/debian-lts-announce/2022/04/msg00006.html
Mailing List
https://security.gentoo.org/glsa/202209-04
Third Party Advisory
https://github.com/uclouvain/openjpeg/issues/1338
Exploit
https://lists.debian.org/debian-lts-announce/2022/04/msg00006.html
Mailing List
https://security.gentoo.org/glsa/202209-04
Third Party Advisory
Analysis
#
Affected Component
Analysis
openjpeg
Patched
Vulnerability Ratings
#
5.5
CVSSv31
4.3
CVSSv2
Others affected components
#
Name
Project
Project Version
Version
Status
openjpeg
buildroot
2025.02.x
2.5.4
Not Affected
openjpeg
buildroot
master
2.5.4
Not Affected
openjpeg
yocto
master
2.5.4
Not Affected
openjpeg
yocto
scarthgap
2.5.4
Not Affected
Resolved with patches
#
openjpeg (yocto:kirkstone)
#
Title
Author
Resolve
1
Fix integer overflow in num_images
Brad Parham <brad.a.parham@intel.com>
CVE-2021-29338