CVE-2024-11498

Publication date 25 November 2024

Last updated 15 July 2025


Ubuntu priority

There exists a stack buffer overflow in libjxl. A specifically-crafted file can cause the JPEG XL decoder to use large amounts of stack space (up to 256mb is possible, maybe 512mb), potentially exhausting the stack. An attacker can craft a file that will cause excessive memory usage. We recommend upgrading past commit 65fbec56bc578b6b6ee02a527be70787bbd053b0.

Status

Package Ubuntu Release Status
jpeg-xl 25.04 plucky
Not affected
24.10 oracular Ignored end of life, was needed
24.04 LTS noble
Fixed 0.7.0-10.2ubuntu6.1
22.04 LTS jammy Not in release
20.04 LTS focal Not in release

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
jpeg-xl

References

Related Ubuntu Security Notices (USN)

Other references