There exists a stack buffer overflow in libjxl. A specifically-crafted file can cause the JPEG XL decoder to use large amounts of stack space (up to 256mb is possible, maybe 512mb), potentially exhausting the stack. An attacker can craft a file that will cause excessive memory usage. We recommend upgrading past commit 65fbec56bc578b6b6ee02a527be70787bbd053b0.
CVSS Details
- CVSS 4.0 Base Score: 6.9 (MEDIUM)
- CVSS 4.0 Vector: (CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade libjxl | Aug 8, 2025 | Nov 25, 2024 |
| Debian | — | Upgrade jpeg-xl | May 15, 2025 | Nov 25, 2024 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Nov 25, 2024 |
| Suse | — | Upgrade libjxl0_8-32bitUpgrade libjxl0_11-x86-64-v3Upgrade libmozjs-115-0Upgrade libjxl0_8-64bitUpgrade libjxl0_11Upgrade jxl-thumbnailerUpgrade libmozjs-128-0Upgrade gimp-plugin-jxlUpgrade mozjs128-develUpgrade libjxl0_8Upgrade mozjs128Upgrade libjxl-toolsUpgrade gdk-pixbuf-loader-jxlUpgrade mozjs115Upgrade mozjs115-develUpgrade libjxl-devel | Jan 3, 2025 | Nov 25, 2024 |
| Ubuntu | — | Upgrade libjpegxl-javaUpgrade libjxl-toolsUpgrade libjxl0.7 | Jul 7, 2025 | Nov 25, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub