#1142282 jbig2dec: CVE-2026-38076

Package:
src:jbig2dec
Source:
src:jbig2dec
Submitter:
Salvatore Bonaccorso
Date:
2026-09-12 09:33:02 UTC
Severity:
normal
Tags:
#1142282#5
Date:
2026-07-17 06:44:17 UTC
From:
To:
Hi,

The following vulnerability was published for jbig2dec.

CVE-2026-38076[0]:
| An integer overflow in the jbig2_arith_iaid_ctx_new() function of
| Artifex commit cc37d0 allows attackers to cause a Denial of Service
| (DoS) via a crafted input.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-38076
https://www.cve.org/CVERecord?id=CVE-2026-38076
[1] https://github.com/ArtifexSoftware/jbig2dec/commit/cc37d0931aa71582f7128736a068c92cd8712d9b

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1142282#12
Date:
2026-09-12 09:32:25 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
jbig2dec, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1142282@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Moritz Mühlenhoff <jmm@debian.org> (supplier of updated jbig2dec package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sun, 30 Aug 2026 20:10:35 +0200
Source: jbig2dec
Architecture: source
Version: 0.20-1+deb13u1
Distribution: trixie-security
Urgency: medium
Maintainer: Debian Printing Team <debian-printing@lists.debian.org>
Changed-By: Moritz Mühlenhoff <jmm@debian.org>
Closes: 1142282
Changes:
 jbig2dec (0.20-1+deb13u1) trixie-security; urgency=medium
 .
   * CVE-2026-38076 (Closes: #1142282)
Checksums-Sha1:
 79bde0dcf746aa3c660007edf0dd82fc8365f5b5 2107 jbig2dec_0.20-1+deb13u1.dsc
 038af4de666d4a98cf375c76d029b85b09921227 149782 jbig2dec_0.20.orig.tar.gz
 91576fa53056792b35ac380aa668a72918652e08 22468 jbig2dec_0.20-1+deb13u1.debian.tar.xz
 6704d4607dc27ee94628f367a54d81d3a2652ac7 7760 jbig2dec_0.20-1+deb13u1_amd64.buildinfo
Checksums-Sha256:
 ab80643a90f118ff818cda5185aae4cc794e502e0f564d543227b23997847ffc 2107 jbig2dec_0.20-1+deb13u1.dsc
 a9705369a6633aba532693450ec802c562397e1b824662de809ede92f67aff21 149782 jbig2dec_0.20.orig.tar.gz
 130b542458b21b5c54f98aeb79ce58c0e793fd0c3fe10745df9046b49704bba6 22468 jbig2dec_0.20-1+deb13u1.debian.tar.xz
 04f4a1536585cc19cb94f247f924045bcc18d57d65726ac3f8d00bae646ecc5f 7760 jbig2dec_0.20-1+deb13u1_amd64.buildinfo
Files:
 33cb2be98c73cd3c548e2fcbfd2a0958 2107 libs optional jbig2dec_0.20-1+deb13u1.dsc
 8777780b182830b2e4c65216f53a909e 149782 libs optional jbig2dec_0.20.orig.tar.gz
 93bcfa5e16e1cc36e9f4ecfe2b51ea4e 22468 libs optional jbig2dec_0.20-1+deb13u1.debian.tar.xz
 ee053987d34d8a9973a32ed14040dc5b 7760 libs optional jbig2dec_0.20-1+deb13u1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmqV6OwACgkQEMKTtsN8
TjY2+w//c7uhJRWTnAyEQXITFnH9Pha/cmbqrkHBgH35p9/axAXClm7X7AOHYY9n
nc4TFshPoHXUWPXlQ1fhEOtlJGEfKNxVyr5VnlD/EOdoX7/RVWXwu2s7OelhSBLc
RZfdTWhImwTlvKfQWc2hPXEt5TEIafZ5eLfI2EdZ6vfuKaL3fg+ntlmBBb1Uj4gx
WP5+MeCiZ4OzFLozm/nZNKQcTePY6y3fmgV3dCsICM/HWPlPxyZ/Fr6B8ovJNG8p
ZIJFRcnJ0LPdGiupeY0peLmSTySigq83dN1ZHyUApeWAp0sefvD1kWsNM3SaWY6R
2qjPhmL/ZREAr+5MUe2GIUmDbYc+gHsJJ2lrgNWp9EK6HkRUWxi3WZdt0u7/zJEn
eLV5pavn7I7HADQivfe45NPtk0ZIZUbIzs8w/U1miru8rvAkRBNXHQbZUarVh6Lp
Nq4V0qT90/4vWv6c7d6zikD7kQi5LnwMy5EvQVxBJ6CbLyMEWnAz6Xx3izdioYsK
apOO4gKyR9dl6kL1cJNyHFFTKIr0RrduJRFaelWNPcyosg5WZ7XU8iP+6NhKCueM
Wv7a9kX/Nwq64iG3FSd5nzMtNKe+9L8QLh0xSJVY0QXFXcKtOu7V+hptEdRLYNGu
nN21ZE78nlFDcwBiReJQ80QIR8sM9eU33CV/bWDIIDWFjbVtsNw=
=wy6+
-----END PGP SIGNATURE-----