ELA-1824-1 jbig2dec security update

denial of service

2026-09-16
Packagejbig2dec
Version0.13-4.1+deb9u2 (stretch), 0.16-1+deb10u2 (buster), 0.19-2+deb11u1 (bullseye)
Related CVEs CVE-2026-38076


It was discovered that missing input sanitising in the JBIG2 decoder library could result in denial of service.



For Debian 10 buster, these problems have been fixed in version 0.16-1+deb10u2.

For Debian 11 bullseye, these problems have been fixed in version 0.19-2+deb11u1.

For Debian 9 stretch, these problems have been fixed in version 0.13-4.1+deb9u2.

We recommend that you upgrade your jbig2dec packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.