Описание
Security update for libjxl
This update for libjxl fixes the following issues:
Security fixes:
- CVE-2025-70103: heap buffer overflow when hen processing crafted pbm-images due to insufficient bounds checks (bsc#1266460).
Other fixes:
- Update to version 0.10.5:
- fix tile dimension in low memory rendering pipeline.
- fix number of channels for gray-to-gray color transform.
djxl: reject decoding JXL files if 'packed' representation size overflows.
- Changes from version 0.10.4:
- Huffman lookup table size fix.
- Check height limit in modular trees.
Список пакетов
SUSE Linux Enterprise Module for Package Hub 15 SP7
libjxl-devel-0.10.5-150700.4.12.1
libjxl-tools-0.10.5-150700.4.12.1
libjxl0_10-0.10.5-150700.4.12.1
libjxl0_10-32bit-0.10.5-150700.4.12.1
Ссылки
- Link for SUSE-SU-2026:2286-1
- E-Mail link for SUSE-SU-2026:2286-1
- SUSE Security Ratings
- SUSE Bug 1266460
- SUSE CVE CVE-2025-70103 page
Описание
Heap buffer overflow vulnerability in libjxl 0.12.0 via crafted PBM images to the jxl::extras::DecodeImagePNM function in file lib/extras/dec/pnm.cc.
Затронутые продукты
SUSE Linux Enterprise Module for Package Hub 15 SP7:libjxl-devel-0.10.5-150700.4.12.1
SUSE Linux Enterprise Module for Package Hub 15 SP7:libjxl-tools-0.10.5-150700.4.12.1
SUSE Linux Enterprise Module for Package Hub 15 SP7:libjxl0_10-0.10.5-150700.4.12.1
SUSE Linux Enterprise Module for Package Hub 15 SP7:libjxl0_10-32bit-0.10.5-150700.4.12.1
Ссылки
- CVE-2025-70103
- SUSE Bug 1266460