← Back

CVE-2021-22563

nvd nist
Published: Nov 1, 2021Modified: Jun 17, 2026

JSON object

Loading...
4.4
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Exploitability: 1.8 / Impact: 2.5
Source: NVD

Description

Invalid JPEG XL images using libjxl can cause an out of bounds access on a std::vector<std::vector<T>> when rendering splines. The OOB read access can either lead to a segfault, or rendering splines based on other process memory. It is recommended to upgrade past 0.6.0 or patch with https://github.com/libjxl/libjxl/pull/757

Affected (1)

Libjxl
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 0.6.0

References (4)

Source: cve-coordination@google.com
ExploitIssue TrackingPatchThird Party Advisory
Source: cve-coordination@google.com
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitIssue TrackingPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory

Timeline

No history available yet.