CVE-2026-39919

Publication date 16 September 2026

Last updated 21 September 2026


Ubuntu priority

Cvss 3 Severity Score

9.8 · Critical

Score breakdown

Description

Ghostscript before 10.08.0 contains a heap-based buffer overflow vulnerability in the JPEG 2000 output adapter (base/sjpx_openjpeg.c) that allows attackers to cause memory corruption by supplying a crafted PDF containing a JPEG 2000 image with mismatched component subsampling factors. When image components declare different subsampling values, the non-samescale sub-byte-depth output path allocates a row buffer sized for packed output but writes a full byte per output column regardless of bit depth, overflowing the allocation and corrupting internal chunk-allocator metadata to achieve code execution.

Status

Package Ubuntu Release Status
ghostscript 26.04 LTS resolute
Fixed 10.06.0~dfsg-3ubuntu1.1
24.04 LTS noble
Fixed 10.02.1~dfsg1-0ubuntu7.9
22.04 LTS jammy
Fixed 9.55.0~dfsg1-0ubuntu5.14
20.04 LTS focal
Needs evaluation
18.04 LTS bionic
Needs evaluation
16.04 LTS xenial
Needs evaluation

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
ghostscript

Severity score breakdown

CVSS version:

Base score 9.3 · Critical

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Base score 9.8 · Critical

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References

Related Ubuntu Security Notices (USN)

    • USN-8791-1
    • Ghostscript vulnerability
    • 21 September 2026

Other references


Access our resources on patching vulnerabilities