{"id":"CVE-2023-2804","details":"A heap-based buffer overflow issue was discovered in libjpeg-turbo in h2v2_merged_upsample_internal() function of jdmrgext.c file. The vulnerability can only be exploited with 12-bit data precision for which the range of the sample data type exceeds the valid sample range, hence, an attacker could craft a 12-bit lossless JPEG image that contains out-of-range 12-bit samples. An application attempting to decompress such image using merged upsampling would lead to segmentation fault or buffer overflows, causing an application to crash.","modified":"2026-08-12T14:50:40.054693Z","published":"2023-05-25T00:00:00Z","related":["CGA-34c5-qwrj-fq2c","openSUSE-SU-2024:13552-1"],"database_specific":{"cna_assigner":"redhat","cwe_ids":["CWE-122"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/2xxx/CVE-2023-2804.json","unresolved_ranges":[{"extracted_events":[{"introduced":"Fixed in libjpeg-turbo v3.0 (beta2)"},{"last_affected":"Fixed in libjpeg-turbo v3.0 (beta2)"}],"source":"AFFECTED_FIELD"}]},"references":[{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2023-2804"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/2xxx/CVE-2023-2804.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-2804"},{"type":"ADVISORY","url":"https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01006.html"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2208447"},{"type":"REPORT","url":"https://github.com/libjpeg-turbo/libjpeg-turbo/issues/668#issuecomment-1492586118"},{"type":"REPORT","url":"https://github.com/libjpeg-turbo/libjpeg-turbo/issues/675"},{"type":"FIX","url":"https://github.com/libjpeg-turbo/libjpeg-turbo/commit/9f756bc67a84d4566bf74a0c2432aa55da404021"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/libjpeg-turbo/libjpeg-turbo","events":[{"introduced":"fd93d98a959ac3700e2da07310a44867c9c46f03"},{"fixed":"9f756bc67a84d4566bf74a0c2432aa55da404021"}],"database_specific":{"source":["CPE_STRING","REFERENCES"],"cpe":"cpe:2.3:a:libjpeg-turbo:libjpeg-turbo:2.1.90:*:*:*:*:*:*:*","extracted_events":[{"introduced":"2.1.90"},{"last_affected":"2.1.90"}]}}],"versions":["2.1.90","2.1.91"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-2804.json","vanir_signatures_modified":"2026-08-12T14:50:40Z","vanir_signatures":[{"target":{"file":"jdlossls.c","function":"noscale"},"deprecated":false,"digest":{"function_hash":"45893349253428892599678605874317640076","length":138},"id":"CVE-2023-2804-2cf6521f","signature_type":"Function","signature_version":"v1","source":"https://github.com/libjpeg-turbo/libjpeg-turbo/commit/9f756bc67a84d4566bf74a0c2432aa55da404021"},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/libjpeg-turbo/libjpeg-turbo/commit/9f756bc67a84d4566bf74a0c2432aa55da404021","target":{"file":"jdlossls.c","function":"simple_upscale"},"deprecated":false,"digest":{"function_hash":"112376369083220100668902696318947702360","length":153},"id":"CVE-2023-2804-41bd6fca"},{"source":"https://github.com/libjpeg-turbo/libjpeg-turbo/commit/9f756bc67a84d4566bf74a0c2432aa55da404021","target":{"file":"jdlossls.c"},"deprecated":false,"digest":{"line_hashes":["264453119585316427186485396598254512130","65582456727176366817468335422094827974","30055463991005291524467097402588854178","310651516989145847112025202950843573985","107740660841104471832336593730836883285","224351062765144820444831876706738103013","320633655483827400771117174154721494510","198497929741904313163517209949287782005","211719071145529734302749623535903388273","8154639209289213855050992008852297386","271144142464856104214596135343707024446"],"threshold":0.9},"id":"CVE-2023-2804-f12af71f","signature_type":"Line","signature_version":"v1"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"}]}