ECHO-07bd-5728-1ad8

See a problem?
Import Source
https://advisory.echohq.com/osv/ECHO-07bd-5728-1ad8.json
JSON Data
https://api.osv.dev/v1/vulns/ECHO-07bd-5728-1ad8
Upstream
Withdrawn
2026-07-20T09:20:35Z
Published
2026-05-24T11:13:48Z
Modified
2026-07-20T09:45:04Z
Summary
Assertion failure (abort/DoS) in jxl::PlaneBase::PlaneBase() reachable only when the cjxl encoder is used to encode a maliciously crafted GIF. There is no memory corruption and no upstream fix: the upstream tracking issues (#422, #762) remain open with no merged commit, and Debian rates the issue "unimportant" with a "Negligible security impact" note and no fixed version in any suite (bookworm through sid). With no upstream remediation available and negligible impact on the libjxl decode path we ship, this is not actionable as a backport.
Details
References

Affected packages

Echo / jpeg-xl

Package

Name
jpeg-xl
Purl
pkg:deb/echo/jpeg-xl

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.11.2-0.1~deb13u2+e1

Database specific

source
"https://advisory.echohq.com/osv/ECHO-07bd-5728-1ad8.json"