{"id":"CVE-2021-45928","details":"libjxl b02d6b9, as used in libvips 8.11 through 8.11.2 and other products, has an out-of-bounds write in jxl::ModularFrameDecoder::DecodeGroup (called from jxl::FrameDecoder::ProcessACGroup and jxl::ThreadPool::RunCallState\u003cjxl::FrameDecoder::ProcessSections).","modified":"2026-08-07T17:03:14.313752Z","published":"2022-01-01T01:15:08.367Z","references":[{"type":"REPORT","url":"https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=36456"},{"type":"FIX","url":"https://github.com/libjxl/libjxl/compare/v0.5...v0.6"},{"type":"FIX","url":"https://github.com/libjxl/libjxl/issues/360"},{"type":"FIX","url":"https://github.com/libjxl/libjxl/pull/365"},{"type":"EVIDENCE","url":"https://github.com/google/oss-fuzz-vulns/blob/main/vulns/libvips/OSV-2021-1055.yaml"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/libjxl/libjxl","events":[{"introduced":"0"},{"fixed":"a205468bc5d3a353fb15dae2398a101dff52f2d3"}],"database_specific":{"cpe":"cpe:2.3:a:libjxl_project:libjxl:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"0.6.1"}],"source":"CPE_RANGE"}}],"versions":["v0.6.0","v0.6","v0.6-base","v0.5-base","v0.3.7","v0.3.6","v0.3.5","v0.3.4","v0.3.3","v0.3.2","v0.3.1","v0.3.0","v0.3","v0.2.0","v0.2","v0.1.1","v0.1.0","v0.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-45928.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}