Vulnerability Description
There exists a stack buffer overflow in libjxl. A specifically-crafted file can cause the JPEG XL decoder to use large amounts of stack space (up to 256mb is possible, maybe 512mb), potentially exhausting the stack. An attacker can craft a file that will cause excessive memory usage. We recommend upgrading past commit 65fbec56bc578b6b6ee02a527be70787bbd053b0.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Libjxl Project | Libjxl | < 0.8.4 |
Related Weaknesses (CWE)
References
- https://github.com/libjxl/libjxl/pull/3943Issue TrackingPatch
FAQ
What is CVE-2024-11498?
CVE-2024-11498 is a vulnerability with a CVSS score of 7.5 (HIGH). There exists a stack buffer overflow in libjxl. A specifically-crafted file can cause the JPEG XL decoder to use large amounts of stack space (up to 256mb is possible, maybe 512mb), potentially exhaus...
How severe is CVE-2024-11498?
CVE-2024-11498 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-11498?
Check the references section above for vendor advisories and patch information. Affected products include: Libjxl Project Libjxl.