CVE-2020-27823: Debian Linux
High severity, CVSS 7.8. EPSS: 1.1% chance of exploitation in the next 30 days.
A flaw was found in OpenJPEG’s encoder. This flaw allows an attacker to pass specially crafted x,y offset input to OpenJPEG to use during encoding. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
Affected products
- Debian Debian Linux: version 9.0 only; version 10.0 only
- Fedoraproject Fedora: version 32 only; version 33 only
- Uclouvain Openjpeg: before 2.4.0 (fixed in 2.4.0)
Published 2021-05-13. Last modified 2026-06-17.