A specially-crafted file can cause libjxl's decoder to read pixel data from uninitialized (but allocated) memory.
This can be done by causing the decoder to reference an outside-image-bound area in a subsequent patches. An incorrect optimization causes the decoder to omit populating those areas.
CVSS Details
- CVSS 4.0 Base Score: 2.3 (LOW)
- CVSS 4.0 Vector: (CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
- CVSS 3.1 Base Score: 4.4
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade libjxl | Jul 15, 2026 | Feb 11, 2026 |
| Amazon Linux Ami 2 | — | Upgrade firefoxUpgrade thunderbird | May 20, 2026 | May 20, 2026 |
| Amazon_linux_2023 | — | Upgrade libjxl-utils-debuginfoUpgrade libjxl-devtools-debuginfoUpgrade firefox-debugsourceUpgrade libjxl-utilsUpgrade firefox-debuginfoUpgrade libjxl-debuginfoUpgrade libjxlUpgrade jpegxl-debugsourceUpgrade jpegxl-docUpgrade libjxl-devtoolsUpgrade jxl-pixbuf-loader-debuginfoUpgrade firefoxUpgrade libjxl-develUpgrade jxl-pixbuf-loaderUpgrade jpegxl-debuginfo | Mar 9, 2026 | Feb 11, 2026 |
| Debian | — | Upgrade jpeg-xl | Jul 23, 2026 | Jul 23, 2026 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Feb 11, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub