CVE-2021-22563

Severity CVSS v4.0:
Pending analysis
Type:
CWE-125 Out-of-bounds Read
Publication date:
01/11/2021
Last modified:
03/11/2021

Description

Invalid JPEG XL images using libjxl can cause an out of bounds access on a std::vector when rendering splines. The OOB read access can either lead to a segfault, or rendering splines based on other process memory. It is recommended to upgrade past 0.6.0 or patch with https://github.com/libjxl/libjxl/pull/757

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:libjxl_project:libjxl:*:*:*:*:*:*:*:* 0.6.0 (excluding)