Search CVE reports


Toggle filters

1 – 7 of 7 results


CVE-2026-1837

Medium priority
Fixed

A specially-crafted file can cause libjxl's decoder to write pixel data to uninitialized unallocated memory. Soon after that data from another uninitialized unallocated region is copied to pixel data. This can be done by...

1 affected package

jpeg-xl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jpeg-xl Not affected Not in release
Show less packages

CVE-2024-11498

Medium priority

Some fixes available 1 of 2

There exists a stack buffer overflow in libjxl. A specifically-crafted file can cause the JPEG XL decoder to use large amounts of stack space (up to 256mb is possible, maybe 512mb), potentially exhausting the stack. An attacker...

1 affected package

jpeg-xl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jpeg-xl Fixed Not in release Not in release
Show less packages

CVE-2024-11403

Medium priority

Some fixes available 1 of 2

There exists an out of bounds read/write in LibJXL versions prior to commit 9cc451b91b74ba470fd72bd48c121e9f33d24c99. The JPEG decoder used by the JPEG XL encoder when doing JPEG recompression (i.e. if using JxlEncoderAddJPEGFrame...

1 affected package

jpeg-xl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jpeg-xl Fixed Not in release Not in release
Show less packages

CVE-2023-35790

Medium priority

Some fixes available 1 of 3

An issue was discovered in dec_patch_dictionary.cc in libjxl before 0.8.2. An integer underflow in patch decoding can lead to a denial of service, such as an infinite loop.

1 affected package

jpeg-xl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jpeg-xl Fixed Not in release Not in release Ignored
Show less packages

CVE-2023-0645

Medium priority

Some fixes available 1 of 3

An out of bounds read exists in libjxl. An attacker using a specifically crafted file could cause an out of bounds read in the exif handler. We recommend upgrading to version 0.8.1 or past...

1 affected package

jpeg-xl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jpeg-xl Fixed Not in release Not in release Not in release
Show less packages

CVE-2021-45928

Medium priority
Ignored

libjxl b02d6b9, as used in libvips 8.11 through 8.11.2 and other products, has an out-of-bounds write in jxl::ModularFrameDecoder::DecodeGroup (called from jxl::FrameDecoder::ProcessACGroup...

1 affected package

jpeg-xl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jpeg-xl
Show less packages

CVE-2021-36691

Negligible priority
Ignored

libjxl v0.5.0 is affected by a Assertion failed issue in lib/jxl/image.cc jxl::PlaneBase::PlaneBase(). When encoding a malicous GIF file using cjxl, an attacker can trigger a denial of service.

1 affected package

jpeg-xl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jpeg-xl Ignored Not in release Not in release Not in release
Show less packages