{"id":"DEBIAN-CVE-2026-39919","details":"Ghostscript before 10.08.0 contains a heap-based buffer overflow vulnerability in the JPEG 2000 output adapter (base/sjpx_openjpeg.c) that allows attackers to cause memory corruption by supplying a crafted PDF containing a JPEG 2000 image with mismatched component subsampling factors. When image components declare different subsampling values, the non-samescale sub-byte-depth output path allocates a row buffer sized for packed output but writes a full byte per output column regardless of bit depth, overflowing the allocation and corrupting internal chunk-allocator metadata to achieve code execution.","modified":"2026-09-27T10:00:06.766370921Z","published":"2026-09-15T15:17:14.723Z","upstream":["CVE-2026-39919"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2026-39919"}],"affected":[{"package":{"name":"ghostscript","ecosystem":"Debian:12","purl":"pkg:deb/debian/ghostscript?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["10.0.0~dfsg-11","10.0.0~dfsg-11+deb12u1","10.0.0~dfsg-11+deb12u2","10.0.0~dfsg-11+deb12u3","10.0.0~dfsg-11+deb12u4","10.0.0~dfsg-11+deb12u5","10.0.0~dfsg-11+deb12u6","10.0.0~dfsg-11+deb12u7","10.0.0~dfsg-11+deb12u8","10.01.2~dfsg-1","10.02.0~dfsg-1","10.02.0~dfsg-2","10.02.1~dfsg-1","10.02.1~dfsg-2","10.02.1~dfsg-3","10.03.0~dfsg-1","10.03.1~dfsg-1","10.03.1~dfsg-2","10.03.1~dfsg~git20240518-1","10.04.0~dfsg-1","10.04.0~dfsg-2","10.05.0~dfsg-1","10.05.1~dfsg-1","10.05.1~dfsg-2","10.05.1~dfsg-3","10.06.0~dfsg-1","10.06.0~dfsg-2","10.06.0~dfsg-3","10.07.0~dfsg-1","10.07.0~dfsg-2","10.07.1~dfsg-1","10.08.0~dfsg-1","10.08.0~dfsg-2"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-39919.json"}},{"package":{"name":"ghostscript","ecosystem":"Debian:13","purl":"pkg:deb/debian/ghostscript?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"10.05.1~dfsg-1+deb13u2"}]}],"versions":["10.05.1~dfsg-1","10.05.1~dfsg-1+deb13u1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-39919.json"}},{"package":{"name":"ghostscript","ecosystem":"Debian:14","purl":"pkg:deb/debian/ghostscript?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"10.08.0~dfsg-1"}]}],"versions":["10.05.1~dfsg-1","10.05.1~dfsg-2","10.05.1~dfsg-3","10.06.0~dfsg-1","10.06.0~dfsg-2","10.06.0~dfsg-3","10.07.0~dfsg-1","10.07.0~dfsg-2","10.07.1~dfsg-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-39919.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"}]}