---
id: CVE-2026-39919
title: >-
  Ghostscript before 10.08.0 contains a heap-based buffer overflow vulnerability
  in the JPEG 2000 output adapter (base/sjpx_openjpeg.c) that allows attackers
  to cause memory corruption by supplying a crafted PDF containing a JPEG 2000
  imag…
summary: >-
  Ghostscript before 10.08.0 contains a heap-based buffer overflow vulnerability
  in the JPEG 2000 output adapter (base/sjpx_openjpeg.c) that allows attackers
  to cause memory corruption by supplying a crafted PDF containing a JPEG 2000
  imag…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-122
vendor: Artifex Software
product: Ghostscript
affected:
  - Ghostscript < 10.08.0
published: '2026-09-15'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T21:04:40.340'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-39919'
references:
  - url: 'https://bugs.ghostscript.com/show_bug.cgi?id=709666'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/ArtifexSoftware/ghostpdl-downloads/releases/tag/gs10080'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/ArtifexSoftware/ghostpdl/commit/0a8bf88e39db07b0751a58d6ec1cf992073e4dc1
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/ghostscript-heap-buffer-overflow-via-jpeg-2000-output-adapter
    label: disclosure@vulncheck.com
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39919.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-39919'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2533857'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-39919'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-39919'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
  - score-dispute
epss: 0.00546
epssPercentile: 0.43395
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-09-20T00:26:01.647179Z'
scores:
  nvd: 9.8
  vendor: 7.8
  cna: 9.8
ingestedAt: '2026-09-15T14:38:16.197Z'
---

## Overview

Ghostscript before 10.08.0 contains a heap-based buffer overflow vulnerability in the JPEG 2000 output adapter (base/sjpx_openjpeg.c) that allows attackers to cause memory corruption by supplying a crafted PDF containing a JPEG 2000 image with mismatched component subsampling factors. When image components declare different subsampling values, the non-samescale sub-byte-depth output path allocates a row buffer sized for packed output but writes a full byte per output column regardless of bit depth, overflowing the allocation and corrupting internal chunk-allocator metadata to achieve code execution.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **Red Hat VEX** · Moderate · affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9 · no fix planned: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, … · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39919.json)
