CVE-2015-8871: Debian Linux

Critical severity, CVSS 9.8. EPSS: 3% chance of exploitation in the next 30 days.

Use-after-free vulnerability in the opj_j2k_write_mco function in j2k.c in OpenJPEG before 2.1.1 allows remote attackers to have unspecified impact via unknown vectors.

Affected products

  • Debian Debian Linux: version 8.0 only
  • Uclouvain Openjpeg: up to and including 2.1.0

Published 2016-09-21. Last modified 2026-06-17.