libjxl v0.5.0 is affected by a Assertion failed issue in lib/jxl/image.cc jxl::PlaneBase::PlaneBase(). When encoding a malicous GIF file using cjxl, an attacker can trigger a denial of service.
{ "binaries": [ { "binary_version": "0.7.0-10.2ubuntu6.1", "binary_name": "libjpegxl-java" }, { "binary_version": "0.7.0-10.2ubuntu6.1", "binary_name": "libjxl-dev" }, { "binary_version": "0.7.0-10.2ubuntu6.1", "binary_name": "libjxl-devtools" }, { "binary_version": "0.7.0-10.2ubuntu6.1", "binary_name": "libjxl-tools" }, { "binary_version": "0.7.0-10.2ubuntu6.1", "binary_name": "libjxl0.7" } ], "priority_reason": "This is just a DoS in out of memory conditions" }
{ "binaries": [ { "binary_version": "0.11.1-4", "binary_name": "libjpegxl-java" }, { "binary_version": "0.11.1-4", "binary_name": "libjxl-dev" }, { "binary_version": "0.11.1-4", "binary_name": "libjxl-devtools" }, { "binary_version": "0.11.1-4", "binary_name": "libjxl-gdk-pixbuf" }, { "binary_version": "0.11.1-4", "binary_name": "libjxl-tools" }, { "binary_version": "0.11.1-4", "binary_name": "libjxl0.11" } ], "priority_reason": "This is just a DoS in out of memory conditions" }