CVE-2024-11498

CVSS V2 None CVSS V3 None
Description
There exists a stack buffer overflow in libjxl. A specifically-crafted file can cause the JPEG XL decoder to use large amounts of stack space (up to 256mb is possible, maybe 512mb), potentially exhausting the stack. An attacker can craft a file that will cause excessive memory usage. We recommend upgrading past commit 65fbec56bc578b6b6ee02a527be70787bbd053b0.
Overview
  • CVE ID
  • CVE-2024-11498
  • Assigner
  • Google
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-11-25T13:08:07.140Z
  • Last Modified Date
  • 2024-11-25T13:55:13.205Z
References
Reference URL Reference Tags
https://github.com/libjxl/libjxl/pull/3943
History
Created Old Value New Value Data Type Notes
2024-11-26 13:15:12 Added to TrackCVE