CVE-2026-39919: Ghostscript JPEG 2000 Heap Buffer Overflow
ID: 730f001d-ee99-5917-a950-2775f86847ed
STIX ID: report--730f001d-ee99-5917-a950-2775f86847ed
Feed Name: CosmicBytez Labs
A critical heap-based buffer overflow (CVE-2026-39919, CVSS 3.1 9.8) exists in Ghostscript's JPEG 2000 output adapter (base/sjpx_openjpeg.c) and can be triggered by a crafted PDF containing a JPEG 2000 image with mismatched subsampling factors; the bug can corrupt heap allocator metadata and potentially be leveraged for code execution. Ghostscript 10.08.0 (2026-09-08) contains the fix; the report recommends updating, checking downstream vendored copies, isolating processing of untrusted PDFs, and monitoring for crashes and anomalous behavior.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
