CVE-2024-11498 is a high-severity stack buffer overflow vulnerability in the libjxl JPEG XL decoder, affecting libjxl_project libjxl. An unauthenticated attacker can trigger excessive memory usage (up to 512MB) by crafting a malicious file, leading to a denial of service. While no active exploits, public exploit code, or significant community discussion have been observed, organizations are advised to upgrade to commit 65fbec56bc578b6b6ee02a527be70787bbd053b0 or later to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.8.4CPE matchmatch criteria | cpe:2.3:a:libjxl_project:libjxl:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.