[CLSA-2026:1787588007] Fix CVE(s): CVE-2021-3575
Type:
security
Severity:
Important
Release date:
2026-08-24 16:13:38 UTC
Description:
* SECURITY UPDATE: off-by-one heap buffer overflow in the YCbCr 4:2:0 to RGB converter - debian/patches/CVE-2021-3575.patch: in src/bin/common/color.c, bound the trailing odd-row loop of sycc420_to_rgb() by loopmaxw instead of maxw and consume the first column with Cb/Cr = 0 when x0 is odd, so the chroma planes are no longer read one sample past their end. - CVE-2021-3575
CVEs fixed:
Updated packages:
  • libopenjp2-7_2.3.0-2+deb10u2build0.18.04.1+tuxcare.els1_amd64.deb
    sha:67a20c019cc98d5e42511295d9f672528feac060
  • libopenjp2-7-dev_2.3.0-2+deb10u2build0.18.04.1+tuxcare.els1_amd64.deb
    sha:d2d20a5024dddb587da951de1a388b8687b30a8e
  • libopenjp2-tools_2.3.0-2+deb10u2build0.18.04.1+tuxcare.els1_amd64.deb
    sha:56647f90f83bb2e14a8921ad6c111ffd2e0f6851
  • libopenjp3d-tools_2.3.0-2+deb10u2build0.18.04.1+tuxcare.els1_amd64.deb
    sha:a765541b17ecc7d422feabc15cd310734d7801e6
  • libopenjp3d7_2.3.0-2+deb10u2build0.18.04.1+tuxcare.els1_amd64.deb
    sha:6a99476b5d936f851ac885f766fb6e99643288d0
  • libopenjpip-dec-server_2.3.0-2+deb10u2build0.18.04.1+tuxcare.els1_amd64.deb
    sha:49cdef014553582b41d71a502cf9fb247a341ce2
  • libopenjpip-server_2.3.0-2+deb10u2build0.18.04.1+tuxcare.els1_amd64.deb
    sha:2882603cbe0b4ce32d3acbf51d2bd97921e5e958
  • libopenjpip-viewer_2.3.0-2+deb10u2build0.18.04.1+tuxcare.els1_all.deb
    sha:ef1506720e06025529fb5328dde95680e8e15530
  • libopenjpip7_2.3.0-2+deb10u2build0.18.04.1+tuxcare.els1_amd64.deb
    sha:e35795ff6207fd03d49cc2992b5d085beb0cc4f6
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.