USN-7637-1

Source
https://ubuntu.com/security/notices/USN-7637-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-7637-1.json
JSON Data
https://api.osv.dev/v1/vulns/USN-7637-1
Upstream
Related
Published
2025-07-14T16:31:56.743643Z
Modified
2025-07-16T21:00:58.982003Z
Summary
jpeg-xl vulnerabilities
Details

It was discovered that libjxl did not perform proper bounds checking when parsing Exif tags. An attacker could possibly use this issue to cause libjxl to crash, resulting in a denial of service. (CVE-2023-0645)

It was discovered that libjxl did not perform proper bounds checking when decoding patches. An attacker could possibly use this issue to cause libjxl to enter an infinite loop, resulting in a denial of service. (CVE-2023-35790)

It was discovered that libjxl did not perform proper bounds checking when performing JPEG recompression. An attacker could possibly use this issue to cause libjxl to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2024-11403)

It was discovered that libjxl incorrectly handled parsing certain image files. An attacker could possibly use this issue to cause libjxl to consume excessive amounts of memory, resulting in a denial of service. (CVE-2024-11498)

References

Affected packages

Ubuntu:24.04:LTS / jpeg-xl

Package

Name
jpeg-xl
Purl
pkg:deb/ubuntu/jpeg-xl@0.7.0-10.2ubuntu6.1?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.7.0-10.2ubuntu6.1

Affected versions

0.*

0.7.0-10ubuntu2
0.7.0-10.2ubuntu1
0.7.0-10.2ubuntu4
0.7.0-10.2ubuntu5
0.7.0-10.2ubuntu6

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_name": "jpeg-xl-doc",
            "binary_version": "0.7.0-10.2ubuntu6.1"
        },
        {
            "binary_name": "libjpegxl-java",
            "binary_version": "0.7.0-10.2ubuntu6.1"
        },
        {
            "binary_name": "libjpegxl-java-dbgsym",
            "binary_version": "0.7.0-10.2ubuntu6.1"
        },
        {
            "binary_name": "libjxl-dev",
            "binary_version": "0.7.0-10.2ubuntu6.1"
        },
        {
            "binary_name": "libjxl-devtools",
            "binary_version": "0.7.0-10.2ubuntu6.1"
        },
        {
            "binary_name": "libjxl-devtools-dbgsym",
            "binary_version": "0.7.0-10.2ubuntu6.1"
        },
        {
            "binary_name": "libjxl-tools",
            "binary_version": "0.7.0-10.2ubuntu6.1"
        },
        {
            "binary_name": "libjxl-tools-dbgsym",
            "binary_version": "0.7.0-10.2ubuntu6.1"
        },
        {
            "binary_name": "libjxl0.7",
            "binary_version": "0.7.0-10.2ubuntu6.1"
        },
        {
            "binary_name": "libjxl0.7-dbgsym",
            "binary_version": "0.7.0-10.2ubuntu6.1"
        }
    ]
}