OSV-2021-1748

See a problem?
Import Source
https://github.com/google/oss-fuzz-vulns/blob/main/vulns/libjxl/OSV-2021-1748.yaml
JSON Data
https://api.osv.dev/v1/vulns/OSV-2021-1748
Published
2021-12-24T00:01:41.024002Z
Modified
2022-04-13T03:04:41.785711Z
Summary
Heap-buffer-overflow in jxl::N_AVX2::FloatToRGBA8
Details

OSS-Fuzz report: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=42839

Crash type: Heap-buffer-overflow WRITE 1
Crash state:
jxl::N_AVX2::FloatToRGBA8
jxl::FinalizeImageRect
jxl::ThreadPool::RunCallState<jxl::FinalizeFrameDecoding
References

Affected packages

OSS-Fuzz / libjxl

Package

Name
libjxl
Purl
pkg:generic/libjxl

Affected ranges

Ecosystem specific

{
    "severity": "HIGH"
}

Database specific

{
    "fixed_range": "ba1932b04bf8db3263372ce5524e35a995d36fa0:33e0c341ba0bde6265752db0009e9be8052897f7"
}