CVE-2025-53367
Publication date 4 July 2025
Last updated 23 February 2026
Ubuntu priority
Description
DjVuLibre is a GPL implementation of DjVu, a web-centric format for distributing documents and images. Prior to version 3.5.29, the MMRDecoder::scanruns method is affected by an OOB-write vulnerability, because it does not check that the xr pointer stays within the bounds of the allocated buffer. This can lead to writes beyond the allocated memory, resulting in a heap corruption condition. An out-of-bounds read with pr is also possible for the same reason. This issue has been patched in version 3.5.29.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| djvulibre | 25.10 questing |
Not affected
|
| 24.04 LTS noble |
Fixed 3.5.28-2ubuntu0.24.04.1
|
|
| 22.04 LTS jammy |
Fixed 3.5.28-2ubuntu0.22.04.1
|
|
| 20.04 LTS focal |
Fixed 3.5.27.1-14ubuntu0.1+esm1
|
|
| 18.04 LTS bionic |
Fixed 3.5.27.1-8ubuntu0.4+esm1
|
|
| 16.04 LTS xenial |
Fixed 3.5.27.1-5ubuntu0.1+esm3
|
Get expanded security coverage with Ubuntu Pro
Reduce your average CVE exposure time from 98 days to 1 day with expanded CVE patching, ten-years security maintenance and optional support for the full stack of open-source applications. Free for personal use.
Get Ubuntu Pro 30-day free trialPatch details
| Package | Patch details |
|---|---|
| djvulibre |
References
Related Ubuntu Security Notices (USN)
- USN-7631-1
- DjVuLibre vulnerability
- 9 July 2025
- USN-8054-1
- DjVuLibre vulnerabilities
- 23 February 2026