NVIDIA nvJPEG2000 library: Improper input validation on a crafted JPEG2000 file causes a partial denial of service
Impact
Improper input validation on a crafted JPEG2000 file causes a partial denial of service in the decoding library. Low severity on its own, but nvJPEG2000 sits inside DALI and medical/geospatial imaging pipelines that ingest customer files by design, so the untrusted-input assumption is real.
Who can reach it
Local, requires the library to decode an attacker-supplied image. Any data-loading pipeline that accepts tenant or customer imagery is the delivery path.
What to do
Update the nvJPEG2000 library per bulletin 5517 and rebuild the images that link it. Cost: package update and job restart only; no driver or firmware change.
References
Related entries
- nvTIFF library: DoS via malformed imageCVE-2024-0080 · nvTIFF libraryLow
- CUDA Toolkit: cuobjdump crashes on malformed ELF input, causing partial denial of serviceCVE-2024-53878 · CUDA ToolkitLow
- CUDA Toolkit: DoS (division by zero)CVE-2025-23273 · CUDA ToolkitLow
- NVIDIA vGPU software - Virtual GPU Manager (host-side vGPU plugin / nvidia.ko): A guest can read global GPU metricsCVE-2025-23290 · NVIDIA vGPU software - Virtual GPU Manager (host-side vGPU plugin / nvidia.ko)Low
- NVIDIA License System - Delegated Licensing Service (DLS): An authorised-looking action leads to information disclosureCVE-2025-23291 · NVIDIA License System - Delegated Licensing Service (DLS)Low
- NVIDIA DGX Spark (GB10) - SROOT / OSROOT root-of-trust firmware: A third resource-reuse path in SROOT firmware leaksCVE-2025-33200 · NVIDIA DGX Spark (GB10) - SROOT / OSROOT root-of-trust firmwareLow
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.