rpm package
suse/libjxl&distro=SUSE Linux Enterprise Module for Package Hub 15 SP7
pkg:rpm/suse/libjxl&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP7
Vulnerabilities (4)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-1837 | Hig | 7.5 | < 0.10.3-150700.4.6.1 | 0.10.3-150700.4.6.1 | Feb 11, 2026 | A specially-crafted file can cause libjxl's decoder to write pixel data to uninitialized unallocated memory. Soon after that data from another uninitialized unallocated region is copied to pixel data. This can be done by requesting color transformation of grayscale images to ano | |
| CVE-2025-12474 | Med | 4.4 | < 0.10.3-150700.4.6.1 | 0.10.3-150700.4.6.1 | Feb 11, 2026 | A specially-crafted file can cause libjxl's decoder to read pixel data from uninitialized (but allocated) memory. This can be done by causing the decoder to reference an outside-image-bound area in a subsequent patches. An incorrect optimization causes the decoder to omit popula | |
| CVE-2024-11403 | — | < 0.10.3-150700.4.3.1 | 0.10.3-150700.4.3.1 | Nov 25, 2024 | There exists an out of bounds read/write in LibJXL versions prior to commit 9cc451b91b74ba470fd72bd48c121e9f33d24c99. The JPEG decoder used by the JPEG XL encoder when doing JPEG recompression (i.e. if using JxlEncoderAddJPEGFrame on untrusted input) does not properly check bound | ||
| CVE-2024-11498 | — | < 0.10.3-150700.4.9.1 | 0.10.3-150700.4.9.1 | Nov 25, 2024 | There exists a stack buffer overflow in libjxl. A specifically-crafted file can cause the JPEG XL decoder to use large amounts of stack space (up to 256mb is possible, maybe 512mb), potentially exhausting the stack. An attacker can craft a file that will cause excessive memory us |
- affected < 0.10.3-150700.4.6.1fixed 0.10.3-150700.4.6.1
A specially-crafted file can cause libjxl's decoder to write pixel data to uninitialized unallocated memory. Soon after that data from another uninitialized unallocated region is copied to pixel data. This can be done by requesting color transformation of grayscale images to ano
- affected < 0.10.3-150700.4.6.1fixed 0.10.3-150700.4.6.1
A specially-crafted file can cause libjxl's decoder to read pixel data from uninitialized (but allocated) memory. This can be done by causing the decoder to reference an outside-image-bound area in a subsequent patches. An incorrect optimization causes the decoder to omit popula
- CVE-2024-11403Nov 25, 2024affected < 0.10.3-150700.4.3.1fixed 0.10.3-150700.4.3.1
There exists an out of bounds read/write in LibJXL versions prior to commit 9cc451b91b74ba470fd72bd48c121e9f33d24c99. The JPEG decoder used by the JPEG XL encoder when doing JPEG recompression (i.e. if using JxlEncoderAddJPEGFrame on untrusted input) does not properly check bound
- CVE-2024-11498Nov 25, 2024affected < 0.10.3-150700.4.9.1fixed 0.10.3-150700.4.9.1
There exists a stack buffer overflow in libjxl. A specifically-crafted file can cause the JPEG XL decoder to use large amounts of stack space (up to 256mb is possible, maybe 512mb), potentially exhausting the stack. An attacker can craft a file that will cause excessive memory us