Heap buffer overflow vulnerability in libjxl 0.12.0 via crafted PBM images to the jxl::extras::DecodeImagePNM function in file lib/extras/dec/pnm.cc.
CVSS Details
- CVSS 3.1 Base Score: 7.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux_2023 | — | Upgrade libjxl-utilsUpgrade jpegxl-debugsourceUpgrade libjxl-utils-debuginfoUpgrade jpegxl-docUpgrade jxl-pixbuf-loader-debuginfoUpgrade libjxl-devtools-debuginfoUpgrade libjxlUpgrade jpegxl-debuginfoUpgrade libjxl-devtoolsUpgrade jxl-pixbuf-loaderUpgrade libjxl-debuginfoUpgrade libjxl-devel | Jun 23, 2026 | May 27, 2026 |
| Debian | — | Upgrade jpeg-xl | Jul 23, 2026 | Jul 23, 2026 |
| Redhat_linux | — | — | Jul 17, 2026 | May 27, 2026 |
| Ubuntu | — | Upgrade libjxl-toolsUpgrade libjxl0.11 | Jun 8, 2026 | May 27, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub