CVE-2021-22563

Name
CVE-2021-22563
Description
Invalid JPEG XL images using libjxl can cause an out of bounds access on a std::vector<std::vector<T>> when rendering splines. The OOB read access can either lead to a segfault, or rendering splines based on other process memory. It is recommended to upgrade past 0.6.0 or patch with https://github.com/libjxl/libjxl/pull/757
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
CONFIRM https://github.com/libjxl/libjxl/issues/735
CONFIRM https://github.com/libjxl/libjxl/pull/757

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:libjxl_project:libjxl:*:*:*:*:*:*:*:* libjxl >= None < 0.6.0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status