CVE-2026-38076 Details
Description
An integer overflow in the jbig2_arith_iaid_ctx_new() function of Artifex commit cc37d0 allows attackers to cause a Denial of Service (DoS) via a crafted input.
A denial-of-service vulnerability has been identified in the Artifex jbig2dec library, specifically in the 'jbig2_arith_iaid_ctx_new()' function. This vulnerability arises from an integer overflow that allows attackers to cause a crash by sending crafted JBIG2 image files. The issue is present in versions prior to the Artifex commit cc37d0.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 9, 2026CISA-ADP
Assessed Jul 10, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://lists.debian.org/debian-lts-announce/2026/09/msg00014.html | CVE | |
| http://artifex.com | [email protected] | Vendor |
| https://gist.github.com/dkjsone/c237b83ffa9ebd7028b5db7f410fcf78 | [email protected] | Technical Description |
| https://github.com/ArtifexSoftware/jbig2dec | [email protected] | ProductSource CodeVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-190 | Integer Overflow or Wraparound | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| Artifex jbig2dec | < https://github.com/ArtifexSoftware/jbig2dec/commit/cc37d0931aa71582f7128736a068c92cd8712d9b |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 14, 2026 | CVE Modified | [email protected] |
| Sep 14, 2026 | CVE Modified | CVE |
| Jul 10, 2026 | CVE Modified | CISA-ADP |
| Jul 9, 2026 | New CVE Received | [email protected] |
Volerion