CVE-2024-11498

There exists a stack buffer overflow in libjxl. A specifically-crafted file can cause the JPEG XL decoder to use large amounts of stack space (up to 256mb is possible, maybe 512mb), potentially exhausting the stack. An attacker can craft a file that will cause excessive memory usage. We recommend upgrading past commit 65fbec56bc578b6b6ee02a527be70787bbd053b0.
References
Link Resource
https://github.com/libjxl/libjxl/pull/3943 Issue Tracking Patch
Configurations

Configuration 1 (hide)

cpe:2.3:a:libjxl_project:libjxl:*:*:*:*:*:*:*:*

History

23 Jul 2025, 19:58

Type Values Removed Values Added
First Time Libjxl Project
Libjxl Project libjxl
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
Summary
  • (es) Existe un desbordamiento del búfer de pila en libjxl. Un archivo creado específicamente puede hacer que el decodificador JPEG XL utilice grandes cantidades de espacio de pila (hasta 256 MB es posible, tal vez 512 MB), lo que podría agotar la pila. Un atacante puede crear un archivo que cause un uso excesivo de la memoria. Recomendamos actualizar a partir de el commit 65fbec56bc578b6b6ee02a527be70787bbd053b0.
References () https://github.com/libjxl/libjxl/pull/3943 - () https://github.com/libjxl/libjxl/pull/3943 - Issue Tracking, Patch
CWE NVD-CWE-noinfo
CPE cpe:2.3:a:libjxl_project:libjxl:*:*:*:*:*:*:*:*

25 Nov 2024, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-25 14:15

Updated : 2025-07-23 19:58


NVD link : CVE-2024-11498

Mitre link : CVE-2024-11498

CVE.ORG link : CVE-2024-11498


JSON object : View

Products Affected

libjxl_project

  • libjxl
CWE
CWE-400

Uncontrolled Resource Consumption

NVD-CWE-noinfo