Opened 8 months ago
Closed 8 months ago
#22781 closed enhancement (fixed)
libjxl-0.11.2
| Reported by: | Bruce Dubbs | Owned by: | Douglas R. Reno |
|---|---|---|---|
| Priority: | high | Milestone: | 13.0 |
| Component: | BOOK | Version: | git |
| Severity: | medium | Keywords: | |
| Cc: |
Description
New point version.
Change History (3)
comment:1 by , 8 months ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
comment:2 by , 8 months ago
| Priority: | normal → high |
|---|
comment:3 by , 8 months ago
| Resolution: | → fixed |
|---|---|
| Status: | assigned → closed |
Fixed at 2fab550f006c25aa84e7e276ca0fd51ccc6d1443
SA-12.4-091 issued
Note:
See TracTickets
for help on using tickets.

Fixed fix tile dimension in low memory rendering pipeline (#4495 - CVE-2025-12474) fix number of channels for gray-to-gray color transform (#4579 - CVE-2026-1837) djxl: reject decoding JXL files if "packed" representation size overflows size_t (#4589 - thanks to Mateusz Jurczyk of Google Project Zero for identifying this issue)CVE-2025-12474 is rated as Low, while CVE-2026-1837 is rated as High. Our configuration in BLFS specifically uses lcms2, so we are *directly* impacted by CVE-2026-1837. That results in significant information disclosure, remote code execution, and denial of service impacts, with no user interaction required (because in a web browser context, this could be exploited just by navigating the web in general)