Updated jbig2dec packages fix security vulnerabilities
Publication date: 31 Aug 2026Modification date: 31 Aug 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2023-46361 , CVE-2026-38076
Description
Artifex Software jbig2dec v0.20 was discovered to contain a SEGV
vulnerability via jbig2_error at /jbig2dec/jbig2.c. (CVE-2023-46361)
An integer overflow in the jbig2_arith_iaid_ctx_new() function of
Artifex commit cc37d0 allows attackers to cause a Denial of Service
(DoS) via a crafted input. (CVE-2026-38076)
References
- https://bugs.mageia.org/show_bug.cgi?id=35994
- https://ubuntu.com/security/notices/USN-8582-1
- https://github.com/Frank-Z7/z-vulnerabilitys/blob/main/jbig2dec-SEGV/jbig2dec-SEGV.md
- https://bugs.ghostscript.com/show_bug.cgi?id=707308
- https://bugs.ghostscript.com/show_bug.cgi?id=705041
- https://www.cve.org/CVERecord?id=CVE-2023-46361
- https://www.cve.org/CVERecord?id=CVE-2026-38076
SRPMS
10/core
- jbig2dec-0.20-2.1.mga10
9/core
- jbig2dec-0.19-4.1.mga9