UbuntuUpdates.org

Package "jpeg-xl"

Name: jpeg-xl

Description:

This package is just an umbrella for a group of other packages, it has no description.
Description samples from packages in group:

  • JPEG XL Image Coding System - "JXL" (documentation)
  • JPEG XL Image Coding System - "JXL" (development files)
  • JPEG XL Plugin for gdk-pixbuf
  • JPEG XL Image Coding System - "JXL" (shared libraries)

Latest version: 0.11.1-6ubuntu1.2
Release: questing (25.10)
Level: security
Repository: main

Links



Other versions of "jpeg-xl" in Questing

Repository Area Version
base main 0.11.1-4
base universe 0.11.1-4
security universe 0.11.1-6ubuntu1.2
updates main 0.11.1-6ubuntu1.2
updates universe 0.11.1-6ubuntu1.2

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 0.11.1-6ubuntu1.2 2026-06-08 13:08:03 UTC

  jpeg-xl (0.11.1-6ubuntu1.2) questing-security; urgency=medium

  * SECURITY UPDATE: Heap buffer overflow via crafted PBM images
    - debian/patches/CVE-2025-70103.patch: Take EC into accound when checking
      required PNM inmput length in lib/extras/dec/pnm.cc.
    - CVE-2025-70103

 -- Marc Deslauriers <email address hidden> Sun, 31 May 2026 12:51:24 -0400

Source diff to previous version
CVE-2025-70103 Heap buffer overflow vulnerability in libjxl 0.12.0 via crafted PBM images to the jxl::extras::DecodeImagePNM function in file lib/extras/dec/pnm.cc.

Version: 0.11.1-6ubuntu1.1 2026-04-02 18:08:51 UTC

  jpeg-xl (0.11.1-6ubuntu1.1) questing-security; urgency=medium

  * SECURITY UPDATE: buffer overflow
    - debian/patches/CVE-2026-1837.patch: Fix allocated buffer lengths in
      lib/jxl/render_pipeline/stage_cms.cc.
    - CVE-2026-1837

 -- Edwin Jiang <email address hidden> Tue, 31 Mar 2026 16:08:54 -0400

CVE-2026-1837 A specially-crafted file can cause libjxl's decoder to write pixel data to uninitialized unallocated memory. Soon after that data from another uninit



About   -   Send Feedback to @ubuntu_updates