{"id":"CVE-2025-12474","summary":"libjxl: Uninitialized memory read in decoder due to incorrect optimization in patch handling","details":"A specially-crafted file can cause libjxl's decoder to read pixel data from uninitialized (but allocated) memory.\n\nThis can be done by causing the decoder to reference an outside-image-bound area in a subsequent patches. An incorrect optimization causes the decoder to omit populating those areas.","modified":"2026-08-12T03:51:11.808279935Z","published":"2026-02-11T15:27:24.118Z","related":["SUSE-SU-2026:0648-1","SUSE-SU-2026:20903-1","openSUSE-SU-2026:10910-1","openSUSE-SU-2026:20385-1"],"database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/12xxx/CVE-2025-12474.json","cna_assigner":"Google","cwe_ids":["CWE-908"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/12xxx/CVE-2025-12474.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-12474"},{"type":"FIX","url":"https://github.com/libjxl/libjxl/pull/4495"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/libjxl/libjxl","events":[{"introduced":"980c90f65f41066cc4959b4eb80eba906867103b"},{"last_affected":"794a5dcf0d54f9f0b20d288a12e87afb91d20dfc"}],"database_specific":{"extracted_events":[{"introduced":"0.7"},{"last_affected":"0.11.1"},{"introduced":"0.7.0"}],"source":["AFFECTED_FIELD","CPE_RANGE"],"cpe":"cpe:2.3:a:libjxl_project:libjxl:*:*:*:*:*:*:*:*"}}],"versions":["v0.11.1","v0.11.0","v0.10-snapshot","v0.9-snapshot","v0.7rc","v0.7-base","v0.8-snapshot"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-12474.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N"}]}