Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-83075.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-83075
Upstream
Published
2026-04-18T07:16:10Z
Modified
2026-08-29T05:25:22Z
Summary
CVE-2026-41254 affecting package openjpeg2 2.3.1-12
Details

Little CMS (lcms2) through 2.18 has an integer overflow in CubeSize in cmslut.c because the overflow check is performed after the multiplication.

References

Affected packages

Azure Linux:3 / openjpeg2

Package

Name
openjpeg2
Purl
pkg:rpm/azure-linux/openjpeg2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
2.3.1-12

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-83075.json"