CVE-2026-38076: Integer Overflow
Published Jul 9, 2026
·Updated
An integer overflow in the jbig2arithiaidctxnew() function of Artifex commit cc37d0 allows attackers to cause a Denial of Service (DoS) via a crafted input.
Affected Software
2 affected components
Artifex Artifex
debian/jbig2dec<=0.19-2, <=0.19-3, <=0.20-1
Event History
Jul 9, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·10:17 PM
DescriptionSeverityWeakness
Jul 21, 2026
Data Sourced
via Ubuntu·07:15 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Launchpad·07:17 PM
Description
Data Sourced
via Debian·07:17 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-38076?
CVE-2026-38076 has a high severity rating of 7.5 according to the CVSS 3.1 scoring system.
2
How do I fix CVE-2026-38076?
To address CVE-2026-38076, it is recommended to update the Artifex library to the latest version that includes the relevant patches.
3
What is the impact of CVE-2026-38076?
CVE-2026-38076 allows attackers to exploit an integer overflow vulnerability leading to a Denial of Service (DoS).
4
What software is affected by CVE-2026-38076?
CVE-2026-38076 affects the Artifex library, specifically the jbig2dec implementation.
5
When was CVE-2026-38076 published?
CVE-2026-38076 was published on July 9, 2026.