Description
Ghostscript before 10.08.0 contains a heap-based buffer overflow vulnerability in the JPEG 2000 output adapter (base/sjpx_openjpeg.c) that allows attackers to cause memory corruption by supplying a crafted PDF containing a JPEG 2000 image with mismatched component subsampling factors. When image components declare different subsampling values, the non-samescale sub-byte-depth output path allocates a row buffer sized for packed output but writes a full byte per output column regardless of bit depth, overflowing the allocation and corrupting internal chunk-allocator metadata to achieve code execution.
Published: 2026-09-15
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

Ghostscript versions earlier than 10.08.0 contain a heap‑based0 output adapter. The flaw occurs when JPEG 2000 images declare different subsampling values for their components. The non‑same‑scale sub‑byte‑depth output path allocates a full byte per output column regardless of the image’s bit depth internal chunk‑allocator metadata and allows the attacker to execute arbitrary code with the privileges of the Ghostscript process.

Affected Systems

Artifex Software Ghostscript running any version before 10.08.0. This includes all installations that process PDFs containing JPEG 2000 images. Use cases such as print services, document converters, or web servers are inferred from the description and are not explicitly stated.

Risk and Exploitability

The vulnerability has a CVSS score of 9.3, indicating critical severity. The EPSS score is 0.00486 (less than 1%), and it is not yet listed in CISA’s KEV catalogue. The attack requires an attacker to supply a malicious PDF that Ghostscript will process, typically through local actions or by exploiting a service that runs Ghostscript. Because the flaw is memory corruption in a commonly used who can influence the input that Ghostscript processes.

Generated by OpenCVE AI on September 17, 2026 at 16:14 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Ghostscript to version 10.08.0 or later.
  • If an update is not immediately possible, restrict Ghostscript usage to trusted input only, run it in a sandboxed environment, and avoid processing, disable JPEG 2000 image processing if the application allows disabling the output adapter; alternatively, filter out JPEG 2000 images with mismatched subsampling before they reach Ghostscript.
  • If the application permits, disable the JPEG 2000 output adapter to eliminate the vulnerability path entirely.

Generated by OpenCVE AI on September 17, 2026 at 16:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6516-1 ghostscript security update
History

Thu, 01 Oct 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Artifex
Artifex ghostscript
CPEs cpe:2.3:a:artifex:ghostscript:*:*:*:*:*:*:*:*
Vendors & Products Artifex
Artifex ghostscript

Mon, 21 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Sun, 20 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description Ghostscript before 10.08.0 contains a heap-based buffer overflow vulnerability in the JPEG 2000 output adapter (base/sjpx_openjpeg.c) that allows attackers to cause memory corruption by supplying a crafted PDF containing a JPEG 2000 image with mismatched component subsampling factors. When image components declare different subsampling values, the non-samescale sub-byte-depth output path allocates a row buffer sized for packed output but writes a full byte per output column regardless of bit depth, overflowing the allocation and corrupting internal chunk-allocator metadata to achieve code execution.
Title Ghostscript < 10.08.0 Heap Buffer Overflow via JPEG 2000 Output Adapter
Weaknesses CWE-122
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Artifex Ghostscript
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-01T15:19:56.598Z

Reserved: 2026-04-07T20:57:06.209Z

Link: CVE-2026-39919

cve-icon Vulnrichment

Updated: 2026-09-20T00:30:39.384Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T15:17:14.723

Modified: 2026-09-24T21:04:40.340

Link: CVE-2026-39919

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-15T14:26:06Z

Links: CVE-2026-39919 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T19:30:06Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow