Home
LOW: 2.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:NDefault status
unaffected
0.7 (semver)
affected
Description
A specially-crafted file can cause libjxl's decoder to read pixel data from uninitialized (but allocated) memory. This can be done by causing the decoder to reference an outside-image-bound area in a subsequent patches. An incorrect optimization causes the decoder to omit populating those areas.
Problem types
CWE-908 Use of Uninitialized Resource
Product status
0.7 (semver)
References
github.com/libjxl/libjxl/pull/4495