CVE-2016-9398: Fedoraproject Fedora

High severity, CVSS 7.5. EPSS: 6% chance of exploitation in the next 30 days.

The jpc_floorlog2 function in jpc_math.c in JasPer before 1.900.17 allows remote attackers to cause a denial of service (assertion failure) via unspecified vectors.

Affected products

  • Fedoraproject Fedora: version 32 only; version 33 only
  • Jasper Project Jasper: before 1.900.17 (fixed in 1.900.17)
  • Opensuse Leap: version 15.1 only; version 15.2 only; version 42.1 only; version 42.2 only
  • Suse Linux Enterprise Desktop: version 12 only
  • Suse Linux Enterprise Server: version 12 only
  • Suse Linux Enterprise Software Development Kit: version 12 only

Published 2017-03-23. Last modified 2026-06-17.