Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-83042.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-83042
Upstream
Published
2026-04-13T17:16:32Z
Modified
2026-08-29T05:25:22Z
Summary
CVE-2026-6192 affecting package openjpeg2 2.3.1-12
Details

A vulnerability was identified in uclouvain openjpeg up to 2.5.4. This impacts the function opjpiinitialise_encode in the library src/lib/openjp2/pi.c. The manipulation leads to integer overflow. The attack must be carried out locally. The exploit is publicly available and might be used. The identifier of the patch is 839936aa33eb8899bbbd80fda02796bb65068951. It is suggested to install a patch to address this issue.

References

Affected packages

Azure Linux:3 / openjpeg2

Package

Name
openjpeg2
Purl
pkg:rpm/azure-linux/openjpeg2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
2.3.1-12

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-83042.json"