CVE-2021-29390: High severity libjpeg-turbo-devel vulnerability
libjpeg-turbo version 2.0.90 has a heap-based buffer over-read (2 bytes) in decompresssmoothdata in jdcoefct.c.
Other sources
libjpeg-turbo version 2.0.90 is vulnerable to a heap-buffer-overflow vulnerability in decompresssmoothdata in jdcoefct.c.
https://bugzilla.redhat.com/showbug.cgi?id=1943797
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-29390?
CVE-2021-29390 is a vulnerability in libjpeg-turbo version 2.0.90 that allows for a heap-based buffer over-read in the decompress_smooth_data function in jdcoefct.c.
What software versions are affected by CVE-2021-29390?
CVE-2021-29390 affects libjpeg-turbo version 2.0.90.
What is the severity of CVE-2021-29390?
The severity of CVE-2021-29390 is high with a CVSS score of 7.1.
How can I fix CVE-2021-29390?
To fix CVE-2021-29390, update to a version of libjpeg-turbo that is not affected by the vulnerability.
Where can I find more information about CVE-2021-29390?
You can find more information about CVE-2021-29390 on the Red Hat Bugzilla page and the libjpeg-turbo GitHub repository.