CVE-2026-75466

NameCVE-2026-75466
Descriptionlibjpeg-turbo 3.2.0 contains an integer division-by-zero vulnerability in the PNG loader. When processing a valid indexed-color PNG image with a non-gray palette through tj3LoadImage12() or tj3LoadImage16() using the default pixel format, the application may trigger a division-by-zero in alloc_sarray(), causing a SIGFPE and denial of service.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
libjpeg-turbo (PTS)bookworm1:2.1.5-2fixed
trixie1:2.1.5-4fixed
forky, sid1:3.1.3-4fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
libjpeg-turbosource(unstable)(not affected)

Notes

- libjpeg-turbo <not-affected> (Vulnerable code introduced later)
https://github.com/libjpeg-turbo/libjpeg-turbo/issues/911
Introduced by: https://github.com/sysfce2/libjpeg-turbo/commit/285744829a1ed5b12dfff61a6a39da0eea0b8405 (3.1.90)
Fixed by: https://github.com/libjpeg-turbo/libjpeg-turbo/commit/f14656395b7c83f66ac248c48dc844caebcc1127

Search for package or bug name: Reporting problems