---
title: "CVE-2016-9572\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2016-9572?format=md
keywords: index, follow
---

# CVE-2016-9572

Publication date 1 August 2018

Last updated 25 August 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**6.5 · Medium**

[Score breakdown](https://ubuntu.com/security/CVE-2016-9572?format=md#impact-score)

Toggle side navigation

## Description

A NULL pointer dereference flaw was found in the way openjpeg 2.1.2 decoded
certain input images. Due to a logic error in the code responsible for
decoding the input image, an application using openjpeg to process image
data could crash when processing a crafted image.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2016-9572?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| openjpeg | 22.10 kinetic | Not in release |
| 22.04 LTS jammy | Not in release |
| 20.04 LTS focal | Not in release |
| 19.04 disco | Not in release |
| 18.10 cosmic | Not in release |
| 18.04 LTS bionic | Not in release |
| 17.10 artful | Not in release |
| 16.04 LTS xenial | Ignored end of standard support |
| 14.04 LTS trusty | Ignored end of standard support |
| openjpeg2 | 22.10 kinetic | Not affected |
| 22.04 LTS jammy | Not affected |
| 20.04 LTS focal | Not affected |
| 18.04 LTS bionic | Not affected |
| 17.10 artful | Ignored end of life |
| 17.04 zesty | Ignored end of life |
| 16.10 yakkety | Ignored end of life |
| 16.04 LTS xenial | Fixed 2.1.2-1.1+deb9u2build0.1 |
| 14.04 LTS trusty | Not in release |
| 12.04 LTS precise | Not in release |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)
* [Patch details](https://ubuntu.com/security/CVE-2016-9572?format=md#patch-details)

## Notes

---

### [ccdm94](https://launchpad.net/~ccdm94)

It seems like commit a817832c223 (szukw000:AFL\_PATCH\_0) was the final
commit created by a contributor in order to fix this issue. This
commit contains the changes in commit 7b28bd2b723 (szukw000:863-862)
which originally attempts to fix this issue. Commit a817832c223
(pull request 895 for more information) contains the changes in commit
7b28bd2b723, which fixes more than just this issue. Commit a817832c223
was never merged, however, and instead, was broken down into various
other commits by upstream, and those were merged instead. These commits
are the following: 178194c0934, 6c4e5bacb9d, 820fcfe8bb1, e03e9474667,
c5bf5ef4d65 and 16aeb9282f6, which are all referenced in pull request
895 (not merged, but the previously mentioned commits reference this
PR and therefore their links can be accessed through it). Parts of
commit a817832c223 have also been refactored and added to commit
0394f8d0f1c, which was actually merged. This commit might also contain
changes which contribute to fixing this issue. However, do note that
this last commit introduced regressions, and further changes had to
be made in order to fix those. More can be seen in pull request 975.
The patches that fix this issue are also related to CVE-2016-9580 and
CVE-2016-9581.

---

### [eslerm](https://launchpad.net/~eslerm)

a non-upstream patch had previously been applied to openjpeg2

---

### [eslerm](https://launchpad.net/~eslerm)

CVE-2016-{9572,9580,9581} use the same patch set CVE-2016-911{3..8} apply merge 0394f8d and commited afterwards

### Patch details

For informational purposes only. We recommend not to cherry-pick updates. [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)

| Package | Patch details |
| --- | --- |
| openjpeg | * Upstream:   [178194c](https://github.com/uclouvain/openjpeg/commit/178194c093422c9564efc41f9ecb5c630b43f723) * Upstream:   [6c4e5ba](https://github.com/uclouvain/openjpeg/commit/6c4e5bacb9d9791fc6ff074bd7958b3820d70514) * Upstream:   [820fcfe](https://github.com/uclouvain/openjpeg/commit/820fcfe8bb101a2862c076b02c9b6b636ce39d2f) * Upstream:   [e03e947](https://github.com/uclouvain/openjpeg/commit/e03e9474667e5117341351699f0b1dbb06f93346) * Upstream:   [c5bf5ef](https://github.com/uclouvain/openjpeg/commit/c5bf5ef4d6552e9159aaad29cb27826acd1a3389) * Upstream:   [16aeb92](https://github.com/uclouvain/openjpeg/commit/16aeb9282f6b3877aa8365c461ba8d3d1338adae) |
| openjpeg2 | * Other:   [7b28bd2](https://github.com/szukw000/openjpeg/commit/7b28bd2b723df6be09fe7791eba33147c1c47d0d) |

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

6.5 · Medium

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Network |
  | Attack complexity | Low |
  | Privileges required | None |
  | User interaction | Required |
  | Scope | Unchanged |
  | Confidentiality impact | None |
  | Integrity impact | None |
  | Availability impact | High |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 6.5 · Medium |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9572)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2016-9572)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2016-9572)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2016-9572)

### Other references

* <https://github.com/uclouvain/openjpeg/issues/863>
* <https://github.com/szukw000/openjpeg/commit/7b28bd2b723df6be09fe7791eba33147c1c47d0d>
* <https://www.cve.org/CVERecord?id=CVE-2016-9572>
