CRITICAL
Out of Bounds read in libjxl
Published Apr 11, 2023
9.1
CRITICALCVSS 3.1
EPSS 0.85%
Description
An out of bounds read exists in libjxl. An attacker using a specifically crafted file could cause an out of bounds read in the exif handler. We recommend upgrading to version 0.8.1 or past commit https://github.com/libjxl/libjxl/pull/2101/commits/d95b050c1822a5b1ede9e0dc937e43fca1b10159 https://github.com/libjxl/libjxl/pull/2101/commits/d95b050c1822a5b1ede9e0dc937e43fca1b10159
Affected products
-
- Version 0.7.0StatusaffectedConstraints<0.8.1
- Version
- < 0.8.1
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- http://www.openwall.com/lists/oss-security/2026/06/29/3
- https://github.com/libjxl/libjxl/pull/2101 Issue TrackingPatch
- https://github.com/libjxl/libjxl/pull/2101/commits/d95b050c1822a5b1ede9e0dc937e43fca1b10159 Patch
| Link | Providers | Tags |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2026/06/29/3 | ||
| https://github.com/libjxl/libjxl/pull/2101 | Issue TrackingPatch | |
| https://github.com/libjxl/libjxl/pull/2101/commits/d95b050c1822a5b1ede9e0dc937e43fca1b10159 | Patch |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Google
Published Apr 11, 2023
Updated Jun 29, 2026
Reserved Feb 2, 2023
Link CVE-2023-0645
CISA Vulnrichment
Updated Feb 7, 2025