CVE-2026-21096: Buffer Overflow
Heap-based buffer overflow in JPEG decoder of libimagecodec.quram.so prior to SMR Sep-2026 Release 1 allows remote attackers to execute arbitrary code.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
libimagecodec.quram.so (JPEG decoder)to a version that resolves this vulnerability.Fixed in SMR Sep-2026 Release 1
Event History
Frequently Asked Questions
What does an attacker need to provide to trigger this issue?
The issue is in the JPEG decoder, so exploitation would require attacker-controlled JPEG content to be processed by the affected library. The available information does not identify a specific delivery channel or application.
Which releases are affected?
Affected releases are versions of libimagecodec.quram.so prior to SMR Sep-2026 Release 1. The provided information does not specify individual device models, OS versions, or library version numbers.
What is the impact if exploitation succeeds?
A remote attacker may be able to execute arbitrary code due to the heap-based buffer overflow in the JPEG decoder.