Vulnerability CVE-2025-50952: Information
Description
openjpeg v 2.5.0 was discovered to contain a NULL pointer dereference via the component /openjp2/dwt.c.
Severity: MEDIUM (6.5)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Fixed packages
Package name | Branch | Fixed in version | Version from repository | Errata ID | Task # | State |
|---|---|---|---|---|---|---|
| libopenjpeg2.0 | sisyphus | 2.5.1-alt1 | 2.5.4-alt1 | ALT-PU-2024-3037-2 | 341475 | Fixed |
| libopenjpeg2.0 | p11 | 2.5.1-alt1 | 2.5.4-alt1 | ALT-PU-2024-3037-2 | 341475 | Fixed |
| libopenjpeg2.0 | c10f2 | 2.5.3-alt1 | 2.5.4-alt1 | ALT-PU-2025-10918-3 | 393308 | Fixed |
| texmaker | sisyphus | 6.0.1-alt2 | 6.0.1-alt2 | ALT-PU-2026-3933-1 | 409772 | Fixed |
| texmaker | sisyphus_loongarch64 | 6.0.1-alt2 | 6.0.1-alt2 | ALT-PU-2026-4033-1 | - | Fixed |
References to Advisories, Solutions, and Tools
Hyperlink | Resource |
|---|---|
| https://github.com/uclouvain/openjpeg/issues/1505 |
|
| https://lists.debian.org/debian-lts-announce/2025/12/msg00035.html | |
| BDU:2025-10831 |