
Upwind Security MDR@UpwindMDR
🚨Critical - Ghostscript RCE via JPEG2000 Heap Overflow (CVE-2026-39919) Ghostscript's JPEG 2000 output adapter in base/sjpx_openjpeg.c allocates an undersized row buffer when parsing a crafted PDF with a JPX image using mismatched component subsampling factors, then performs out-of-bounds writes. Heap corruption can lead to process crash or potential code execution. 👉Affected: Ghostscript < 10.08.0 | Upgrade to 10.08.0
1000086
304 followersView on X
