Introducing Wiz for Exposure Management: Unify, prioritize, and remediate exposures everywhere.

CVE-2025-54874
Linux Debian vulnerability analysis and mitigation

Overview

OpenJPEG, an open-source JPEG 2000 codec, contains a vulnerability (CVE-2025-54874) discovered in version 2.5.3 and earlier versions. The vulnerability was disclosed on August 5, 2025, and involves a potential out-of-bounds heap memory write condition that occurs when calling opjjp2readheader with a too short data stream and an uninitialized pimage (NVD).

Technical details

The vulnerability stems from a failure to check the return value of opjj2kreadheader() before processing its output arguments in opjjp2readheader(). When opjj2kreadheaderprocedure() fails while obtaining marker segment data due to a short data stream, opjj2kreadheader() cannot initialize pimage, leaving it uninitialized. The vulnerability has been assigned a CVSS v4.0 score of 6.6 (Medium) with vector string CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P (NVD, GitHub PR).

Impact

The vulnerability can lead to an out-of-bounds heap memory write when processing specially crafted JPEG 2000 images. The exploitability depends on the specific usage of the OpenJPEG library, and the uninitialized variable could potentially contain arbitrary memory addresses. This could result in memory corruption and potentially lead to arbitrary code execution (GitHub Advisory).

Mitigation and workarounds

A fix has been implemented in commit f809b80c67717c152a5ad30bf06774f00da4fd2d, which adds a check for the return value of opjj2kreadheader() before using the output argument pimage. Users should upgrade to a version containing this fix (GitHub Commit).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management