[CLSA-2026:1776849467] jasper: Fix of 3 CVEs
Type:
security
Severity:
Important
Release date:
2026-04-25 08:37:48 UTC
Description:
- CVE-2021-26926: prevent out-of-bounds read in jp2_decode by hard-erroring on inconsistent IHDR/BPCC component metadata - CVE-2021-26927: prevent out-of-bounds read in jp2_decode by hard-erroring on inconsistent IHDR/BPCC component metadata - CVE-2021-3272: prevent heap-based buffer over-read in jp2_decode by hard-erroring when the decoder channel count exceeds the image component count
Updated packages:
  • jasper-1.900.1-33.el7.tuxcare.els5.x86_64.rpm
    sha:d792745beb442b62813466bc7cfab93a4c28d608c6ec0d910aee11db5d69f7fe
  • jasper-devel-1.900.1-33.el7.tuxcare.els5.i686.rpm
    sha:383eb7146148fe671ef6e6074c5203484d4e996842d3763ed438bbfe2d924ce7
  • jasper-devel-1.900.1-33.el7.tuxcare.els5.x86_64.rpm
    sha:ef620c7dfd2aa8f3f1f5ee8d683b31e5f345fc38870cef742d718aceab7f91bb
  • jasper-libs-1.900.1-33.el7.tuxcare.els5.i686.rpm
    sha:4028bf80b5e2befea138a6ce61123e63694a3960c59b649f34cade9877f0c347
  • jasper-libs-1.900.1-33.el7.tuxcare.els5.x86_64.rpm
    sha:4b9e8eff27aa37ba6e0473c3beae7a6b31bb1aad961d3266628e69c9f6b49e1b
  • jasper-utils-1.900.1-33.el7.tuxcare.els5.x86_64.rpm
    sha:612a72aaec72de8a6db96d18ab3c340afd4e45f4264c2a32a9b0903da7338928
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.