PT-2023-3326 · Libjxl+5 · Libjxl+5

Rfrohl

·

Published

2023-06-15

·

Updated

2025-07-14

·

CVE-2023-35790

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions libjxl versions prior to 0.8.2
Description An issue in dec patch dictionary.cc can lead to a denial of service due to an integer underflow in patch decoding, potentially causing an infinite loop. The issue can be exploited by a remote attacker to disrupt service.
Recommendations For versions prior to 0.8.2, update to version 0.8.2 or later to resolve the issue. As a temporary workaround, consider restricting the use of the dec patch dictionary.cc component until a patch is available.

Fix

DoS

Integer Underflow

Weakness Enumeration

Related Identifiers

ALT-PU-2023-2000
ALT-PU-2024-2593
BDU:2023-03481
CVE-2023-35790
DSA-5958-1
OPENSUSE-SU-2023:0161-1
USN-7637-1

Affected Products

Alt Linux
Debian
Linuxmint
Red Os
Ubuntu
Libjxl