CVE-2016-9675: Red Hat Enterprise Linux

High severity, CVSS 7.8. EPSS: 1.9% chance of exploitation in the next 30 days.

openjpeg: A heap-based buffer overflow flaw was found in the patch for CVE-2013-6045. A crafted j2k image could cause the application to crash, or potentially execute arbitrary code.

Affected products

  • Red Hat Enterprise Linux: version 6.0 only; version 7.0 only; version 7.3 only; version 7.4 only; version 7.5 only; version 7.6 only; …
  • Red Hat Enterprise Linux For IBM Z Systems: version 6.0 only
  • Red Hat Enterprise Linux For Power Big Endian: version 6.0 only
  • Red Hat Enterprise Linux For Scientific Computing: version 6.0 only
  • Uclouvain Openjpeg: before 1.5.2 (fixed in 1.5.2)

Published 2016-12-22. Last modified 2026-06-17.