PT-2026-7615 · Lcms2+1 · Lcms2+1

Novomesk

·

Published

2026-01-01

·

Updated

2026-05-11

·

CVE-2026-1837

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions libjxl (affected versions not specified)
Description A crafted file can lead to libjxl's decoder writing pixel data to uninitialized and unallocated memory. Subsequently, data from another uninitialized region is copied to pixel data. This occurs when requesting color transformation of grayscale images to another grayscale color space. Specifically, buffers allocated for 1-float-per-pixel are incorrectly used as if they are allocated for 3-float-per-pixel. This behavior is observed only when LCMS2 is utilized as the Color Management System (CMS) engine. An alternative CMS engine is available and selectable during the build process.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-1837
OPENSUSE-SU-2026:10271-1
OPENSUSE-SU-2026:20385-1
SUSE-SU-2026:0648-1
SUSE-SU-2026:20903-1
USN-8146-1

Affected Products

Lcms2
Libjxl