There exists an out of bounds read/write in LibJXL versions prior to commit 9cc451b91b74ba470fd72bd48c121e9f33d24c99. The JPEG decoder used by the JPEG XL encoder when doing JPEG recompression (i.e. if using JxlEncoderAddJPEGFrame on untrusted input) does not properly check bounds in the presence of incomplete codes. This could lead to an out-of-bounds write. In jpegli which is released as part of the same project, the same vulnerability is present. However, the relevant buffer is part of a bigger structure, and the code makes no assumptions on the values that could be overwritten. The issue could however cause jpegli to read uninitialised memory, or addresses of functions.
CVSS Details
- CVSS 4.0 Base Score: 6.9 (MEDIUM)
- CVSS 4.0 Vector: (CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:P/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade libjxl | Aug 8, 2025 | Nov 25, 2024 |
| Amazon Linux Ami 2 | — | Upgrade thunderbirdUpgrade thunderbird-debuginfo | Apr 17, 2025 | Nov 25, 2024 |
| Debian | — | Upgrade jpeg-xl | May 15, 2025 | Nov 25, 2024 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Nov 25, 2024 |
| Suse | — | Upgrade qt6-pdfquick-private-develUpgrade gimp-plugin-jxlUpgrade libjxl-toolsUpgrade gdk-pixbuf-loader-jxlUpgrade libjxl0_8-32bitUpgrade mozjs128-develUpgrade mozjs115-develUpgrade libmozjs-128-0Upgrade libjxl0_11Upgrade qt6-pdfwidgets-private-develUpgrade libjxl0_11-x86-64-v3Upgrade libjxl0_8-64bitUpgrade libQt6WebEngineCore6Upgrade libQt6WebEngineWidgets6Upgrade qt6-webenginequick-develUpgrade libQt6Pdf6Upgrade qt6-pdf-develUpgrade qt6-pdf-importsUpgrade qt6-webenginequick-private-develUpgrade qt6-pdfwidgets-develUpgrade qt6-webengine-docs-htmlUpgrade qt6-webengine-importsUpgrade qt6-pdf-private-develUpgrade libjxl-develUpgrade qt6-webengine-docs-qchUpgrade mozjs115Upgrade jxl-thumbnailerUpgrade qt6-webenginecore-private-develUpgrade qt6-pdfquick-develUpgrade qt6-webenginecore-develUpgrade qt6-webengine-examplesUpgrade libQt6PdfQuick6Upgrade libjxl0_8Upgrade libQt6WebEngineQuick6Upgrade mozjs128Upgrade libmozjs-115-0Upgrade qt6-webenginewidgets-develUpgrade libQt6PdfWidgets6Upgrade qt6-webengineUpgrade qt6-webenginewidgets-private-devel | Jan 3, 2025 | Nov 25, 2024 |
| Ubuntu | — | Upgrade libjxl-toolsUpgrade libjpegxl-javaUpgrade libjxl0.7 | Jul 7, 2025 | Nov 25, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub