CVE-2021-26927: Null Pointer Dereference
A flaw was found in jasper before 2.0.25. A null pointer dereference in jp2decode in jp2dec.c may lead to program crash and denial of service.
Other sources
A flaw was found in jasper. A null pointer dereference in jp2decode in jp2dec.c may lead to program crash and denial of service.
Upstream issue:
https://github.com/jasper-software/jasper/issues/265
Upstream patch:
https://github.com/jasper-software/jasper/commit/41f214b121b837fa30d9ca5f2430212110f5cd9b
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-26927?
CVE-2021-26927 is a vulnerability in jasper before version 2.0.25 that may lead to a program crash and denial of service due to a null pointer dereference.
How does CVE-2021-26927 impact the system?
CVE-2021-26927 can cause the program to crash and result in a denial of service.
What is the severity of CVE-2021-26927?
The severity of CVE-2021-26927 is medium (5.5).
Which software versions are affected by CVE-2021-26927?
Versions before 2.0.25 of jasper are affected by CVE-2021-26927.
How can CVE-2021-26927 be fixed?
To fix CVE-2021-26927, update jasper to version 2.0.25 or later.