Vulnerabilities > CVE-2021-45928 - Out-of-bounds Write vulnerability in Libjxl Project Libjxl
Attack vector
LOCAL Attack complexity
LOW Privileges required
LOW Confidentiality impact
NONE Integrity impact
NONE Availability impact
HIGH Summary
libjxl b02d6b9, as used in libvips 8.11 through 8.11.2 and other products, has an out-of-bounds write in jxl::ModularFrameDecoder::DecodeGroup (called from jxl::FrameDecoder::ProcessACGroup and jxl::ThreadPool::RunCallState<jxl::FrameDecoder::ProcessSections).
Vulnerable Configurations
Common Weakness Enumeration (CWE)
References
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=36456
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=36456
- https://github.com/google/oss-fuzz-vulns/blob/main/vulns/libvips/OSV-2021-1055.yaml
- https://github.com/google/oss-fuzz-vulns/blob/main/vulns/libvips/OSV-2021-1055.yaml
- https://github.com/libjxl/libjxl/compare/v0.5...v0.6
- https://github.com/libjxl/libjxl/compare/v0.5...v0.6
- https://github.com/libjxl/libjxl/issues/360
- https://github.com/libjxl/libjxl/issues/360
- https://github.com/libjxl/libjxl/pull/365
- https://github.com/libjxl/libjxl/pull/365