Opened 8 months ago

Closed 8 months ago

#22781 closed enhancement (fixed)

libjxl-0.11.2

Reported by: Bruce Dubbs Owned by: Douglas R. Reno
Priority: high Milestone: 13.0
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

New point version.

Change History (3)

comment:1 by Douglas R. Reno, 8 months ago

Owner: changed from blfs-book to Douglas R. Reno
Status: new → assigned

comment:2 by Douglas R. Reno, 8 months ago

Priority: normal → high
Fixed

    fix tile dimension in low memory rendering pipeline (#4495 -
    CVE-2025-12474)
    fix number of channels for gray-to-gray color transform (#4579 -
    CVE-2026-1837)
    djxl: reject decoding JXL files if "packed" representation size overflows
    size_t (#4589 - thanks to Mateusz Jurczyk of Google Project Zero for
    identifying this issue)

CVE-2025-12474 is rated as Low, while CVE-2026-1837 is rated as High. Our configuration in BLFS specifically uses lcms2, so we are *directly* impacted by CVE-2026-1837. That results in significant information disclosure, remote code execution, and denial of service impacts, with no user interaction required (because in a web browser context, this could be exploited just by navigating the web in general)

comment:3 by Douglas R. Reno, 8 months ago

Resolution: → fixed
Status: assigned → closed

Fixed at 2fab550f006c25aa84e7e276ca0fd51ccc6d1443

SA-12.4-091 issued

Note: See TracTickets for help on using tickets.