A vulnerability, identified as CVE-2026-38076 with a CVSS score of 7.5, exists in the JBIG2 decoder library due to missing input sanitizing. This flaw allows an attacker to send specially crafted data to the JBIG2 decoder library, potentially causing applications such as MuPDF to crash or consume excessive resources, impacting business operations and leading to financial losses. The vulnerability is a denial-of-service issue that could be exploited through various attack vectors, including network attacks and local exploitation. Users are recommended to upgrade their jbig2dec packages to mitigate this issue.
We recommend you to update jbig2dec to version 0.20-1+deb13u1 or later.[/subscribe_to_unlock_form]
A vulnerability, identified as CVE-2026-38076 with a CVSS score of 7.5, exists in the JBIG2 decoder library due to missing input sanitizing. This flaw allows an attacker to send specially crafted data to the JBIG2 decoder library, potentially causing applications such as MuPDF to crash or consume excessive resources, impacting business operations and leading to financial losses. The vulnerability is a denial-of-service issue that could be exploited through various attack vectors, including network attacks and local exploitation. Users are recommended to upgrade their jbig2dec packages to mitigate this issue.
We recommend you to update jbig2dec to version 0.20-1+deb13u1 or later.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]