{"id":"GHSA-2v8p-fqpx-2q3w","summary":"jxl-oxide: integer subtraction overflow panic in cluster_from_table via crafted JXL input (DoS)","details":"### Summary\nLogic bug in `decode_simple_table_slow` may cause integer arithmetic overflow when decoding Modular image with certain kind of MA tree, which may panic with `overflow-checks` enabled.\n\n### Impact\nDenial of service: any application passing untrusted JXL data to `JxlImage::render_frame` (or equivalent) can be\ncrashed. Affects all builds with overflow checks enabled, which includes debug builds and any release build\nthat sets `overflow-checks = true` in Cargo.toml or `[profile.*]`.\n\nNo memory corruption is possible — the panic fires before any unsafe code is reached.","modified":"2026-07-02T21:00:18.159260333Z","published":"2026-07-02T20:44:57Z","database_specific":{"cwe_ids":["CWE-190"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-07-02T20:44:57Z","nvd_published_at":null},"references":[{"type":"WEB","url":"https://github.com/tirr-c/jxl-oxide/security/advisories/GHSA-2v8p-fqpx-2q3w"},{"type":"PACKAGE","url":"https://github.com/tirr-c/jxl-oxide"}],"affected":[{"package":{"name":"jxl-modular","ecosystem":"crates.io","purl":"pkg:cargo/jxl-modular"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.11.3"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 0.11.2","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-2v8p-fqpx-2q3w/GHSA-2v8p-fqpx-2q3w.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}