Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-39919— Ghostscript < 10.08.0 Heap Buffer Overflow via JPEG 2000 Output Adapter

Quick assessment

Affected
Artifex Software Ghostscript
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Ghostscript 10.08.0 之前的版本在 JPEG 2000 输出适配器( )中存在一个基于堆的缓冲区溢出漏洞。攻击者可以通过提供一个包含 JPEG 2000 图像的经过精心构造的 PDF 文件,使图像各分量的子采样因子不匹配,从而引发内存破坏。当图像分量声明了不同的子采样值时,非同比例(non-samescale)且子字节深度的输出路径会分配一个按打包输出大小计算的行缓冲区,但无论实际位深度如何,每列输出均写入完整的 1 字节,导致超出分配大小,破坏内部块分配器元数据,进而可能导致代码执行。

CVSS 9.8 · Critical

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 1

VendorProduct Version RangeStatus
Artifex Software Ghostscript < 10.08.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-39919

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Ghostscript < 10.08.0 Heap Buffer Overflow via JPEG 2000 Output Adapter
Source: CVE Program / CVE List V5
Vulnerability Description
Ghostscript before 10.08.0 contains a heap-based buffer overflow vulnerability in the JPEG 2000 output adapter (base/sjpx_openjpeg.c) that allows attackers to cause memory corruption by supplying a crafted PDF containing a JPEG 2000 image with mismatched component subsampling factors. When image components declare different subsampling values, the non-samescale sub-byte-depth output path allocates a row buffer sized for packed output but writes a full byte per output column regardless of bit depth, overflowing the allocation and corrupting internal chunk-allocator metadata to achieve code execution.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
堆缓冲区溢出
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Artifex Software Ghostscript 0 ~ 10.08.0 -

II. Public POCs for CVE-2026-39919

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-39919

登录查看更多情报信息。

Patches & Fixes for CVE-2026-39919 (1)

Vendor Advisories for CVE-2026-39919 (1)

Vendor Pages for CVE-2026-39919 (2)

IV. Related Vulnerabilities

V. Comments for CVE-2026-39919

No comments yet


Leave a comment