OSV-2026-616

See a problem?
Import Source
https://github.com/google/oss-fuzz-vulns/blob/main/vulns/kimageformats/OSV-2026-616.yaml
JSON Data
https://api.osv.dev/v1/vulns/OSV-2026-616
Published
2026-04-24T00:20:25.044744Z
Modified
2026-04-24T00:20:25.045135Z
Summary
Use-of-uninitialized-value in JXRHandlerPrivate::colorSpace
Details

OSS-Fuzz report: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=505263965

Crash type: Use-of-uninitialized-value
Crash state:
JXRHandlerPrivate::colorSpace
JXRHandlerPrivate::imageFormat
JXRHandler::read
References

Affected packages

OSS-Fuzz / kimageformats

Package

Name
kimageformats
Purl
pkg:generic/kimageformats

Affected ranges

Type
GIT
Repo
https://invent.kde.org/frameworks/kimageformats.git
Events
Introduced
1b3f32a332e0735da75c9cb4fbdeb35c00f5cb82
Fixed
51db11eefcc9936b6e2aa6995edba19390c62057

Ecosystem specific

{
    "severity": "MEDIUM"
}

Database specific

fixed_range
"d5e5012cfb125bc243043808d31a36b3c70e3e58:51db11eefcc9936b6e2aa6995edba19390c62057"
introduced_range
"7cf60da031f77bb8573ecc8610b8c4f0a5c78741:d5e5012cfb125bc243043808d31a36b3c70e3e58"
source
"https://github.com/google/oss-fuzz-vulns/blob/main/vulns/kimageformats/OSV-2026-616.yaml"