---
id: CVE-2020-6851
title: >-
  OpenJPEG through 2.3.1 has a heap-based buffer overflow in
  opj_t1_clbl_decode_processor in openjp2/t1.c because of lack of
  opj_j2k_update_image_dimensions validation.
summary: >-
  OpenJPEG through 2.3.1 has a heap-based buffer overflow in
  opj_t1_clbl_decode_processor in openjp2/t1.c because of lack of
  opj_j2k_update_image_dimensions validation.
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-787
  - CWE-122
vendor: uclouvain
product: openjpeg
affected:
  - openjpeg <= 2.3.1
  - fedora = 30
  - fedora = 31
  - debian_linux = 8.0
  - debian_linux = 9.0
  - debian_linux = 10.0
  - enterprise_linux = 8.0
  - enterprise_linux_desktop = 7.0
  - enterprise_linux_eus = 7.7
  - enterprise_linux_eus = 8.1
  - enterprise_linux_eus = 8.2
  - enterprise_linux_eus = 8.4
  - enterprise_linux_server = 7.0
  - enterprise_linux_server_aus = 7.7
  - enterprise_linux_server_aus = 8.2
  - enterprise_linux_server_aus = 8.4
  - enterprise_linux_server_tus = 7.7
  - enterprise_linux_server_tus = 8.2
  - enterprise_linux_server_tus = 8.4
  - enterprise_linux_workstation = 7.0
  - georaster = 18c
  - outside_in_technology = 8.5.4
  - outside_in_technology = 8.5.5
published: '2020-01-13'
updated: '2026-09-22'
sourceUpdated: '2026-09-22T18:17:08.367'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2020-6851'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2020:0262'
    label: cve@mitre.org
  - url: 'https://access.redhat.com/errata/RHSA-2020:0274'
    label: cve@mitre.org
  - url: 'https://access.redhat.com/errata/RHSA-2020:0296'
    label: cve@mitre.org
  - url: 'https://github.com/uclouvain/openjpeg/issues/1228'
    label: cve@mitre.org
  - url: 'https://lists.debian.org/debian-lts-announce/2020/01/msg00025.html'
    label: cve@mitre.org
  - url: 'https://lists.debian.org/debian-lts-announce/2020/07/msg00008.html'
    label: cve@mitre.org
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LACIIDDCKZJEPKTTFILSOSBQL7L3FC6V/
    label: cve@mitre.org
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XBRMI2D3XPVWKE3V52KRBW7BJVLS5LD3/
    label: cve@mitre.org
  - url: 'https://www.debian.org/security/2021/dsa-4882'
    label: cve@mitre.org
  - url: 'https://www.oracle.com/security-alerts/cpujul2020.html'
    label: cve@mitre.org
  - url: 'http://www.openwall.com/lists/oss-security/2026/09/22/6'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2020:0262'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2020:0274'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2020:0296'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://github.com/uclouvain/openjpeg/issues/1228'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2020/01/msg00025.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2020/07/msg00008.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LACIIDDCKZJEPKTTFILSOSBQL7L3FC6V/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XBRMI2D3XPVWKE3V52KRBW7BJVLS5LD3/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.debian.org/security/2021/dsa-4882'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpujul2020.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2020/cve-2020-6851.json
  - url: 'https://access.redhat.com/security/cve/CVE-2020-6851'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=1790511'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2020-6851'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2020-6851'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
epss: 0.05185
epssPercentile: 0.92147
ingestedAt: '2026-09-22T18:08:12.502Z'
patched:
  - enterprise_linux_client_v_7
  - enterprise_linux_client_optional_v_7
  - enterprise_linux_computenode_v_7
  - enterprise_linux_computenode_optional_v_7
  - enterprise_linux_server_v_7
  - enterprise_linux_server_optional_v_7
  - enterprise_linux_workstation_v_7
  - enterprise_linux_workstation_optional_v_7
  - enterprise_linux_appstream_e4s_v_8_0
  - enterprise_linux_appstream_v_8
  - codeready_linux_builder_v_8
scores:
  nvd: 7.5
  vendor: 8.1
---

## Overview

OpenJPEG through 2.3.1 has a heap-based buffer overflow in opj_t1_clbl_decode_processor in openjp2/t1.c because of lack of opj_j2k_update_image_dimensions validation.

## Affected

- `openjpeg <= 2.3.1`
- `fedora = 30`
- `fedora = 31`
- `debian_linux = 8.0`
- `debian_linux = 9.0`
- `debian_linux = 10.0`
- `enterprise_linux = 8.0`
- `enterprise_linux_desktop = 7.0`
- `enterprise_linux_eus = 7.7`
- `enterprise_linux_eus = 8.1`
- `enterprise_linux_eus = 8.2`
- `enterprise_linux_eus = 8.4`
- `enterprise_linux_server = 7.0`
- `enterprise_linux_server_aus = 7.7`
- `enterprise_linux_server_aus = 8.2`
- `enterprise_linux_server_aus = 8.4`
- `enterprise_linux_server_tus = 7.7`
- `enterprise_linux_server_tus = 8.2`
- `enterprise_linux_server_tus = 8.4`
- `enterprise_linux_workstation = 7.0`
- `georaster = 18c`
- `outside_in_technology = 8.5.4`
- `outside_in_technology = 8.5.5`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **RHSA-2020:0262** · Red Hat · fixed in: Red Hat Enterprise Linux Client (v. 7), Red Hat Enterprise Linux Client Optional (v. 7), Red Hat Enterprise Linux ComputeNode (v. 7), Red Hat Enterprise Linux ComputeNode Optional (v. 7), Red Hat Enterprise Linux Server (v. 7), Red Hat Enterprise Linux Server Optional (v. 7), … · released 2020-01-28 · [advisory](https://access.redhat.com/errata/RHSA-2020:0262)
- **RHSA-2020:0296** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v. 8.0) · released 2020-01-30 · [advisory](https://access.redhat.com/errata/RHSA-2020:0296)
- **RHSA-2020:0274** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 8), Red Hat CodeReady Linux Builder (v. 8) · released 2020-01-29 · [advisory](https://access.redhat.com/errata/RHSA-2020:0274)
