CVE-2020-14152: Debian Linux

High severity, CVSS 7.1. EPSS: 1.5% chance of exploitation in the next 30 days.

In IJG JPEG (aka libjpeg) before 9d, jpeg_mem_available() in jmemnobs.c in djpeg does not honor the max_memory_to_use setting, possibly causing excessive memory consumption.

Affected products

  • Debian Debian Linux: version 9.0 only
  • Ijg Libjpeg: before 9d (fixed in 9d)

Published 2020-06-15. Last modified 2026-06-17.