yocto ▾
›
kirkstone ▾
›
vulnerability
›
CVE-2021-3575
Component Overview
Vulnerability Overview
Name
CVE-2021-3575
Source
NVD (
link
)
Debian (
link
)
Description
A heap-based buffer overflow was found in openjpeg in color.c:379:42 in sycc420_to_rgb when decompressing a crafted .j2k file. An attacker could use this to execute arbitrary code with the permissions of the application compiled against openjpeg.
CWEs
CWE-787
CWE-787
Published Date
Mar 4, 2022
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://bugzilla.redhat.com/show_bug.cgi?id=1957616
Issue Tracking
https://github.com/uclouvain/openjpeg/issues/1347
Exploit
https://ubuntu.com/security/CVE-2021-3575
Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=1957616
Issue Tracking
https://github.com/uclouvain/openjpeg/issues/1347
Exploit
https://ubuntu.com/security/CVE-2021-3575
Third Party Advisory
Analysis
#
Affected Component
Analysis
openjpeg
Patched
Vulnerability Ratings
#
7.8
CVSSv31
6.8
CVSSv2
Others affected components
#
Name
Project
Project Version
Version
Status
openjpeg
buildroot
2025.02.x
2.5.4
Not Affected
openjpeg
buildroot
master
2.5.4
Not Affected
openjpeg
yocto
master
2.5.4
Not Affected
openjpeg
yocto
scarthgap
2.5.4
Not Affected
Resolved with patches
#
openjpeg (yocto:kirkstone)
#
Title
Author
Resolve
1
opj_decompress: fix off-by-one read heap-buffer-overflow in
Even Rouault <even.rouault@spatialys.com>
CVE-2021-3575