CVE-2026-1837
Gravedad CVSS v4.0:
ALTA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
11/02/2026
Última modificación:
11/02/2026
Descripción
*** Pendiente de traducción *** A specially-crafted file can cause libjxl&#39;s decoder to write pixel data to uninitialized unallocated memory. Soon after that data from another uninitialized unallocated region is copied to pixel data.<br />
<br />
This can be done by requesting color transformation of grayscale images to another grayscale color space. Buffers allocated for 1-float-per-pixel are used as if they are allocated for 3-float-per-pixel. That happens only if LCMS2 is used as CMS engine. There is another CMS engine available (selected by build flags).
Impacto
Puntuación base 4.0
8.70
Gravedad 4.0
ALTA



