MGASA-2026-0344

Source
https://advisories.mageia.org/MGASA-2026-0344.html
Import Source
https://advisories.mageia.org/MGASA-2026-0344.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2026-0344
Upstream
  • CVE-2026-38076
Published
2026-08-31T16:22:02Z
Modified
2026-08-31T16:30:04.403347236Z
Summary
Updated jbig2dec packages fix security vulnerabilities
Details

Artifex Software jbig2dec v0.20 was discovered to contain a SEGV vulnerability via jbig2error at /jbig2dec/jbig2.c. (CVE-2023-46361) An integer overflow in the jbig2arithiaidctx_new() function of Artifex commit cc37d0 allows attackers to cause a Denial of Service (DoS) via a crafted input. (CVE-2026-38076)

References
Credits

Affected packages

Mageia:10 / jbig2dec

Package

Name
jbig2dec
Purl
pkg:rpm/mageia/jbig2dec?arch=source&distro=mageia-10

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.20-2.1.mga10

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2026-0344.json"

Mageia:9 / jbig2dec

Package

Name
jbig2dec
Purl
pkg:rpm/mageia/jbig2dec?arch=source&distro=mageia-9

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.19-4.1.mga9

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2026-0344.json"