Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-70103

Опубликовано: 27 мая 2026
Источник: redhat
CVSS3: 7.6
EPSS Низкий

Описание

Heap buffer overflow vulnerability in libjxl 0.12.0 via crafted PBM images to the jxl::extras::DecodeImagePNM function in file lib/extras/dec/pnm.cc.

A flaw was found in libjxl, an image processing library. This heap buffer overflow vulnerability could potentially allow a remote attacker to cause a denial of service. The flaw occurs when processing specially crafted PBM (Portable Bitmap) images, primarily impacting applications that handle untrusted image content.

Отчет

This Important heap buffer overflow in libjxl occurs when processing specially crafted PBM images. The vulnerability primarily impacts applications that handle untrusted image content, requiring user interaction to trigger the flaw. This is considered Important due to the potential for denial of service, even with user interaction.

Меры по смягчению последствий

Upstream has fixed this issue in PR #4338. To mitigate this flaw update to a libjxl version containing the fix once it becomes available.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10firefoxAffected
Red Hat Enterprise Linux 10thunderbirdAffected
Red Hat Enterprise Linux 8thunderbirdAffected
Red Hat Enterprise Linux 9thunderbirdAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=2482205libjxl: libjxl: Arbitrary code execution via crafted PBM images

EPSS

Процентиль: 29%
0.00367
Низкий

7.6 High

CVSS3

Связанные уязвимости

CVSS3: 7.3
ubuntu
3 месяца назад

Heap buffer overflow vulnerability in libjxl 0.12.0 via crafted PBM images to the jxl::extras::DecodeImagePNM function in file lib/extras/dec/pnm.cc.

CVSS3: 7.3
nvd
3 месяца назад

Heap buffer overflow vulnerability in libjxl 0.12.0 via crafted PBM images to the jxl::extras::DecodeImagePNM function in file lib/extras/dec/pnm.cc.

CVSS3: 7.3
debian
3 месяца назад

Heap buffer overflow vulnerability in libjxl 0.12.0 via crafted PBM im ...

suse-cvrf
2 месяца назад

Security update for mozjs128

suse-cvrf
2 месяца назад

Security update for libjxl

EPSS

Процентиль: 29%
0.00367
Низкий

7.6 High

CVSS3