libjxl v0.5.0 is affected by a Assertion failed issue in lib/jxl/image.cc jxl::PlaneBase::PlaneBase(). When encoding a malicous GIF file using cjxl, an attacker can trigger a denial of service.
{
"priority_reason": "This is just a DoS in out of memory conditions",
"binaries": [
{
"binary_name": "libjpegxl-java",
"binary_version": "0.7.0-10.2ubuntu6.1"
},
{
"binary_name": "libjxl-dev",
"binary_version": "0.7.0-10.2ubuntu6.1"
},
{
"binary_name": "libjxl-devtools",
"binary_version": "0.7.0-10.2ubuntu6.1"
},
{
"binary_name": "libjxl-tools",
"binary_version": "0.7.0-10.2ubuntu6.1"
},
{
"binary_name": "libjxl0.7",
"binary_version": "0.7.0-10.2ubuntu6.1"
}
]
}
{
"priority_reason": "This is just a DoS in out of memory conditions",
"binaries": [
{
"binary_name": "libjpegxl-java",
"binary_version": "0.11.1-4"
},
{
"binary_name": "libjxl-dev",
"binary_version": "0.11.1-4"
},
{
"binary_name": "libjxl-devtools",
"binary_version": "0.11.1-4"
},
{
"binary_name": "libjxl-gdk-pixbuf",
"binary_version": "0.11.1-4"
},
{
"binary_name": "libjxl-tools",
"binary_version": "0.11.1-4"
},
{
"binary_name": "libjxl0.11",
"binary_version": "0.11.1-4"
}
]
}