{"id":"CVE-2022-32978","details":"There is an assertion failure in SingleComponentLSScan::ParseMCU in singlecomponentlsscan.cpp in libjpeg before 1.64 via an empty JPEG-LS scan.","modified":"2026-07-23T08:25:05.549289Z","published":"2022-06-10T14:49:06Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/32xxx/CVE-2022-32978.json","unresolved_ranges":[{"extracted_events":[{"fixed":"1.64"}],"source":"DESCRIPTION"}],"cna_assigner":"mitre"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/32xxx/CVE-2022-32978.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-32978"},{"type":"REPORT","url":"https://github.com/thorfdbg/libjpeg/issues/75"},{"type":"FIX","url":"https://github.com/thorfdbg/libjpeg/commit/4746b577931e926a49e50de9720a4946de3069a7"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/thorfdbg/libjpeg","events":[{"introduced":"0"},{"fixed":"4746b577931e926a49e50de9720a4946de3069a7"}],"database_specific":{"source":"REFERENCES"}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-32978.json","vanir_signatures_modified":"2026-07-23T08:25:05Z","vanir_signatures":[{"id":"CVE-2022-32978-55200ea4","signature_type":"Function","signature_version":"v1","source":"https://github.com/thorfdbg/libjpeg/commit/4746b577931e926a49e50de9720a4946de3069a7","target":{"file":"codestream/sampleinterleavedlsscan.cpp","function":"SampleInterleavedLSScan::ParseMCU"},"deprecated":false,"digest":{"function_hash":"163515957555476654476716648341094672251","length":2810}},{"deprecated":false,"digest":{"function_hash":"311285046678055315024752986528906340906","length":2328},"id":"CVE-2022-32978-5689dc72","signature_type":"Function","signature_version":"v1","source":"https://github.com/thorfdbg/libjpeg/commit/4746b577931e926a49e50de9720a4946de3069a7","target":{"file":"codestream/singlecomponentlsscan.cpp","function":"SingleComponentLSScan::ParseMCU"}},{"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["280594311517971789971203805469285792835","152281044020064936939215788550432439759","262519431338909069941027999591901449611","197514939160667512479996465199404682623","198321237115231452784671131740169231885","317299035883896088909785713870291028212","321259370930290079189657963577302053983","122386116870419651546625519921519775685"]},"id":"CVE-2022-32978-8798bcde","signature_type":"Line","signature_version":"v1","source":"https://github.com/thorfdbg/libjpeg/commit/4746b577931e926a49e50de9720a4946de3069a7","target":{"file":"codestream/sampleinterleavedlsscan.cpp"}},{"deprecated":false,"digest":{"line_hashes":["279784259655055939818511820799877684835","198321237115231452784671131740169231885","133851965833139932519803887623922890079","64937156121700232804210135073088639598","236524264625233893874486566012351735951"],"threshold":0.9},"id":"CVE-2022-32978-b7b8509b","signature_type":"Line","signature_version":"v1","source":"https://github.com/thorfdbg/libjpeg/commit/4746b577931e926a49e50de9720a4946de3069a7","target":{"file":"codestream/singlecomponentlsscan.cpp"}}]}}],"schema_version":"1.7.5"}