NVIDIA nvJPEG2000 library: Improper input validation on a crafted JPEG2000 file causes a partial denial of service
Impact
Improper input validation on a crafted JPEG2000 file causes a partial denial of service in the decoding library. Low severity on its own, but nvJPEG2000 sits inside DALI and medical/geospatial imaging pipelines that ingest customer files by design, so the untrusted-input assumption is real.
Who can reach it
Local, requires the library to decode an attacker-supplied image. Any data-loading pipeline that accepts tenant or customer imagery is the delivery path.
What to do
Update the nvJPEG2000 library per bulletin 5517 and rebuild the images that link it. Cost: package update and job restart only; no driver or firmware change.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.