openSUSE-SU-2025:0139-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2025:0139-1.json
JSON Data
https://api.osv.dev/v1/vulns/openSUSE-SU-2025:0139-1
Related
Published
2025-04-30T12:01:35Z
Modified
2025-05-07T18:15:42.179444Z
Upstream
Summary
Security update for libjxl
Details

This update for libjxl fixes the following issues:

  • Update to release 0.8.4
    • Huffman lookup table size fix [CVE-2024-11403]
    • Check height limit in modular trees [CVE-2024-11498]
References

Affected packages

SUSE:Package Hub 15 SP6 / libjxl

Package

Name
libjxl
Purl
pkg:rpm/suse/libjxl&distro=SUSE%20Package%20Hub%2015%20SP6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.8.4-bp156.3.3.4

Ecosystem specific

{
    "binaries": [
        {
            "libjxl-tools": "0.8.4-bp156.3.3.4",
            "libjxl0_8-32bit": "0.8.4-bp156.3.3.4",
            "jxl-thumbnailer": "0.8.4-bp156.3.3.4",
            "libjxl0_8": "0.8.4-bp156.3.3.4",
            "gimp-plugin-jxl": "0.8.4-bp156.3.3.4",
            "libjxl-devel": "0.8.4-bp156.3.3.4",
            "gdk-pixbuf-loader-jxl": "0.8.4-bp156.3.3.4",
            "libjxl0_8-64bit": "0.8.4-bp156.3.3.4"
        }
    ]
}

SUSE:Package Hub 15 SP6 / libjxl-gtk

Package

Name
libjxl-gtk
Purl
pkg:rpm/suse/libjxl-gtk&distro=SUSE%20Package%20Hub%2015%20SP6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.8.4-bp156.3.3.4

Ecosystem specific

{
    "binaries": [
        {
            "libjxl-tools": "0.8.4-bp156.3.3.4",
            "libjxl0_8-32bit": "0.8.4-bp156.3.3.4",
            "jxl-thumbnailer": "0.8.4-bp156.3.3.4",
            "libjxl0_8": "0.8.4-bp156.3.3.4",
            "gimp-plugin-jxl": "0.8.4-bp156.3.3.4",
            "libjxl-devel": "0.8.4-bp156.3.3.4",
            "gdk-pixbuf-loader-jxl": "0.8.4-bp156.3.3.4",
            "libjxl0_8-64bit": "0.8.4-bp156.3.3.4"
        }
    ]
}

openSUSE:Leap 15.6 / libjxl

Package

Name
libjxl
Purl
pkg:rpm/opensuse/libjxl&distro=openSUSE%20Leap%2015.6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.8.4-bp156.3.3.4

Ecosystem specific

{
    "binaries": [
        {
            "libjxl-tools": "0.8.4-bp156.3.3.4",
            "libjxl0_8-32bit": "0.8.4-bp156.3.3.4",
            "jxl-thumbnailer": "0.8.4-bp156.3.3.4",
            "libjxl0_8": "0.8.4-bp156.3.3.4",
            "gimp-plugin-jxl": "0.8.4-bp156.3.3.4",
            "libjxl-devel": "0.8.4-bp156.3.3.4",
            "gdk-pixbuf-loader-jxl": "0.8.4-bp156.3.3.4",
            "libjxl0_8-64bit": "0.8.4-bp156.3.3.4"
        }
    ]
}

openSUSE:Leap 15.6 / libjxl-gtk

Package

Name
libjxl-gtk
Purl
pkg:rpm/opensuse/libjxl-gtk&distro=openSUSE%20Leap%2015.6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.8.4-bp156.3.3.4

Ecosystem specific

{
    "binaries": [
        {
            "libjxl-tools": "0.8.4-bp156.3.3.4",
            "libjxl0_8-32bit": "0.8.4-bp156.3.3.4",
            "jxl-thumbnailer": "0.8.4-bp156.3.3.4",
            "libjxl0_8": "0.8.4-bp156.3.3.4",
            "gimp-plugin-jxl": "0.8.4-bp156.3.3.4",
            "libjxl-devel": "0.8.4-bp156.3.3.4",
            "gdk-pixbuf-loader-jxl": "0.8.4-bp156.3.3.4",
            "libjxl0_8-64bit": "0.8.4-bp156.3.3.4"
        }
    ]
}