Denial of Service Vulnerabilities in jbig2dec Affect Ubuntu 22.04 LTS

Denial of Service Vulnerabilities in jbig2dec Affect Ubuntu 22.04 LTS

First seen 22 Jul 2026, 02:53 UTC UbuntuLinuxsecurity 90% similarity 57.1

Article Content

Browse articles
ThreatCluster

Two vulnerabilities were discovered in jbig2dec, a JBIG2 decoder library, affecting Ubuntu 22.04 LTS. The first, an out-of-bounds read vulnerability (CVE-2023-46361), could cause the tool to crash, leading to denial of service. The second, an integer overflow (CVE-2026-38076), also poses a risk of denial of service. Both vulnerabilities were identified by researchers Zeng Yunxiang and Song Jiaxuan. Affected users are advised to update their systems to mitigate these issues. The vulnerabilities were disclosed on July 9, 2026, and have been addressed in recent security updates. Ubuntu Pro offers extended security coverage for affected systems.

Key Points: • Two denial of service vulnerabilities found in jbig2dec affecting Ubuntu 22.04 LTS. • CVE-2023-46361 involves an out-of-bounds read, while CVE-2026-38076 is an integer overflow. • Users are urged to update their systems to mitigate these vulnerabilities.

ThreatCluster AI

Timeline

2023-10-31
CVE-2023-46361 published
An out-of-bounds read vulnerability in jbig2dec was officially published, affecting Ubuntu 22.04 LTS.
Ubuntu
2026-07-09
CVE-2026-38076 published
An integer overflow vulnerability in jbig2dec was published, posing a denial of service risk.
Ubuntu
2026-07-21
Security updates released for jbig2dec
Ubuntu released updates to address the vulnerabilities in jbig2dec, urging users to apply them.
Linuxsecurity

Community

Browse all →