Vulnerability Details CVE-2021-22563
Invalid JPEG XL images using libjxl can cause an out of bounds access on a std::vector<std::vector<T>> when rendering splines. The OOB read access can either lead to a segfault, or rendering splines based on other process memory. It is recommended to upgrade past 0.6.0 or patch with https://github.com/libjxl/libjxl/pull/757
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 13.6%
CVSS Severity
CVSS v3 Score 4.5
CVSS v2 Score 3.6
Products affected by CVE-2021-22563
-
cpe:2.3:a:libjxl_project:libjxl:-
-
cpe:2.3:a:libjxl_project:libjxl:0.1
-
cpe:2.3:a:libjxl_project:libjxl:0.1.1
-
cpe:2.3:a:libjxl_project:libjxl:0.2
-
cpe:2.3:a:libjxl_project:libjxl:0.3
-
cpe:2.3:a:libjxl_project:libjxl:0.3.1
-
cpe:2.3:a:libjxl_project:libjxl:0.3.2
-
cpe:2.3:a:libjxl_project:libjxl:0.3.3
-
cpe:2.3:a:libjxl_project:libjxl:0.3.4
-
cpe:2.3:a:libjxl_project:libjxl:0.3.5
-
cpe:2.3:a:libjxl_project:libjxl:0.3.6
-
cpe:2.3:a:libjxl_project:libjxl:0.3.7
-
cpe:2.3:a:libjxl_project:libjxl:0.5
-
cpe:2.3:a:libjxl_project:libjxl:0.6