CVE-2020-0296
NixOS vulnerability analysis and mitigation

Overview

A heap-based buffer overflow vulnerability was discovered in OpenJPEG through version 2.3.1. The vulnerability, identified as CVE-2020-6851, exists in the opj_t1_clbl_decode_processor function within the openjp2/t1.c file due to insufficient validation in opj_j2k_update_image_dimensions (MITRE CVE).

Technical details

The vulnerability is specifically located in the opj_t1_clbl_decode_processor function of OpenJPEG's source code, affecting the image dimension validation process. The issue stems from inadequate validation in the opj_j2k_update_image_dimensions functionality, which could lead to a heap-based buffer overflow condition (GitHub Issue).

Impact

The vulnerability affects OpenJPEG, an open-source library used for reading and writing image files in JPEG2000 format. When exploited, the heap-based buffer overflow could potentially lead to memory corruption and possible code execution (Red Hat Advisory).

Mitigation and workarounds

Various vendors have released security updates to address this vulnerability. Red Hat has provided patches for Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions, and Debian has also issued security updates through DSA-4882 (Red Hat Advisory, Debian Advisory).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-75874CRITICAL10
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesAug 18, 2026
CVE-2026-74990CRITICAL9.8
  • NixOS logoNixOS
  • thunderbird
NoYesAug 18, 2026
CVE-2026-74989CRITICAL9.8
  • NixOS logoNixOS
  • thunderbird
NoYesAug 18, 2026
CVE-2026-74988CRITICAL9.8
  • NixOS logoNixOS
  • thunderbird
NoYesAug 18, 2026
CVE-2026-74987CRITICAL9.8
  • NixOS logoNixOS
  • MozillaFirefox
NoYesAug 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management