Related Vulnerabilities: CVE-2021-22563  

Invalid JPEG XL images using libjxl before version 0.6.1 can cause an out of bounds access on a std::vector<std::vector<T>> when rendering splines. The OOB read access can either lead to a segfault, or rendering splines based on other process memory.

Severity Medium

Remote Yes

Type Information disclosure

Description

Invalid JPEG XL images using libjxl before version 0.6.1 can cause an out of bounds access on a std::vector<std::vector<T>> when rendering splines. The OOB read access can either lead to a segfault, or rendering splines based on other process memory.

AVG-2508 libjxl 0.6-1 0.6.1-1 Medium Fixed

https://github.com/libjxl/libjxl/issues/735
https://github.com/libjxl/libjxl/pull/757
https://github.com/libjxl/libjxl/commit/b0b39694d8ba6eb031eae217fcae488ce7403ae7