| Package | jbig2dec |
|---|---|
| Version | 0.13-4.1+deb9u2 (stretch), 0.16-1+deb10u2 (buster), 0.19-2+deb11u1 (bullseye) |
| Related CVEs | CVE-2026-38076 |
It was discovered that missing input sanitising in the JBIG2 decoder library could result in denial of service.
For Debian 10 buster, these problems have been fixed in version 0.16-1+deb10u2.
For Debian 11 bullseye, these problems have been fixed in version 0.19-2+deb11u1.
For Debian 9 stretch, these problems have been fixed in version 0.13-4.1+deb9u2.
We recommend that you upgrade your jbig2dec packages.
Further information about Extended LTS security advisories can be found in the dedicated section of our website.