VYPR
Medium severity5.5NVD Advisory· Published Jan 1, 2022· Updated Jun 17, 2026

CVE-2021-45928

CVE-2021-45928

Description

libjxl b02d6b9, as used in libvips 8.11 through 8.11.2 and other products, has an out-of-bounds write in jxl::ModularFrameDecoder::DecodeGroup (called from jxl::FrameDecoder::ProcessACGroup and jxl::ThreadPool::RunCallState<jxl::FrameDecoder::ProcessSections).

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • cpe:2.3:a:libjxl_project:libjxl:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:libjxl_project:libjxl:*:*:*:*:*:*:*:*range: <0.6.1
    • (no CPE)range: <=v0.6
  • libvips/libjxldescription
  • Libvips/Libvipsllm-fuzzy
    Range: 8.11 - 8.11.2

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.