CVE-2020-14153
NixOS vulnerability analysis and mitigation

Overview

CVE-2020-14153 affects IJG JPEG (also known as libjpeg) versions 8 through 9c. The vulnerability involves an out-of-bounds array read for certain table pointers in the jdhuff.c file (NVD, CVE). The issue was discovered and disclosed on June 15, 2020.

Technical details

The vulnerability exists in the jdhuff.c file where there is an out-of-bounds array read condition related to table pointers. The fix implemented in version 9d involves modifying how AC tables are handled, specifically by adding a check to ensure AC tables are only used when present: entropy->ac_cur_tbls[blkn] = cinfo->lim_Se ? entropy->ac_derived_tbls[compptr->ac_tbl_no] : NULL (Gentoo Bug).

Impact

The vulnerability could potentially lead to information disclosure through out-of-bounds array reads. The CVSS v3.1 base score is 7.1 (High), with impact metrics showing high confidentiality and availability impacts, while integrity remains unaffected (Ubuntu).

Exploitability

The vulnerability requires local access and user interaction to exploit, with low attack complexity and no privileges required. The attack vector is local, indicating that the attacker needs local access to the target system to exploit the vulnerability (Ubuntu).

Mitigation and workarounds

The vulnerability was fixed in IJG JPEG version 9d. Users should upgrade to this version or later to mitigate the issue. It's worth noting that libjpeg-turbo, a separate implementation, is not affected by this vulnerability as confirmed by the project maintainers (Libjpeg-turbo Issue).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-75874CRITICAL10
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesAug 18, 2026
CVE-2026-74990CRITICAL9.8
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesAug 18, 2026
CVE-2026-74989CRITICAL9.8
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesAug 18, 2026
CVE-2026-74988CRITICAL9.8
  • NixOS logoNixOS
  • thunderbird
NoYesAug 18, 2026
CVE-2026-74987CRITICAL9.8
  • NixOS logoNixOS
  • MozillaFirefox-branding-upstream
NoYesAug 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management