Source: jpeg-xl Version: 0.11.2-5.1 Severity: important Tags: security upstream Forwarded: https://github.com/libjxl/libjxl/pull/4885 X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerability was published for jpeg-xl. CVE-2026-82522[0]: | libjxl before 0.12 contains an integer underflow vulnerability in | the container box parser that allows remote attackers to inject | arbitrary metadata by exploiting 64-bit box size truncation to | size_t on 32-bit platforms. Attackers can supply a crafted JPEG XL | file causing the decoder to parse attacker-controlled codestream | bytes as phantom box headers, enabling injection of arbitrary | metadata (Exif, XMP, IPTC, JUMBF) and potential out-of-bounds reads. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-82522 https://www.cve.org/CVERecord?id=CVE-2026-82522 [1] https://github.com/libjxl/libjxl/pull/4885 [2] https://github.com/libjxl/libjxl/commit/22ad80af1454f0444ea34115e49ed40517147d68 Please adjust the affected versions in the BTS as needed. Regards, Salvatore

