yocto ▾
›
kirkstone ▾
›
vulnerability
›
CVE-2024-56826
Component Overview
Vulnerability Overview
Name
CVE-2024-56826
Source
NVD (
link
)
Debian (
link
)
Description
A flaw was found in the OpenJPEG project. A heap buffer overflow condition may be triggered when certain options are specified while using the opj_decompress utility. This can lead to an application crash or other undefined behavior.
CWEs
CWE-122
Published Date
Jan 9, 2025
Updated Date
Jun 17, 2026
Workaround
-
Advisories
Analysis
#
Affected Component
Analysis
openjpeg
Patched
Vulnerability Ratings
#
5.6
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
openjpeg
buildroot
2025.02.x
2.5.4
Not Affected
openjpeg
buildroot
master
2.5.4
Not Affected
openjpeg
yocto
master
2.5.4
Not Affected
openjpeg
yocto
scarthgap
2.5.4
Not Affected
Resolved with patches
#
openjpeg (yocto:kirkstone)
#
Title
Author
Resolve
1
sycc422_to_rgb(): fix out-of-bounds read accesses when 2 *
Even Rouault <even.rouault@spatialys.com>
CVE-2024-56826