{"id":"GHSA-5pmv-rx8r-wmv5","summary":"jxl-grid on 32-bit platforms has an out-of-bounds writes due to integer overflow","details":"### Summary\n\nOn 32-bit platforms, decoding a crafted image may lead to out-of-bounds writes due to integer overflow in length calculation.\n\n### Details & PoC\n\nThe test listed below fail under miri with command `cargo +nightly miri test --release -p jxl-grid`\n\nOr you can use Address Sanitizer, which ignores Rust-specific UB like aliasing but still flags out-of-bounds accesses:\n\n`RUSTFLAGS=-Zsanitizer=address cargo +nightly test -Zbuild-std -p jxl-grid --release --target x86_64-unknown-linux-gnu`\n\nThe following tests should be appended to `crates/jxl-grid/src/test/subgrids.rs`:\n\n```rust\nmod miri_ub {\n    use super::*;\n\n    // `AlignedGrid::with_alloc_tracker` computes `width * height` unchecked. In release, overflow\n    // can create a tiny backing buffer for huge logical dimensions.\n    #[test]\n    fn aligned_grid_dimension_product_overflows() {\n        let width = usize::MAX / 2 + 1;\n        let mut grid = AlignedGrid::\u003cu8\u003e::with_alloc_tracker(width, 2, None).unwrap();\n        let mut subgrid = grid.as_subgrid_mut();\n        *subgrid.get_mut(0, 1) = 1;\n        std::hint::black_box(grid);\n    }\n}\n```\n\nThis issue can be reachable through decoding a crafted image in two ways:\n\n1. **Huge actual frame**\n   A frame such as `65536 x 65536` passes the current frame area limit (`2^32 \u003c= 2^40`) but overflows `usize` element count on 32-bit. Rendering then allocates too-small `AlignedGrid`s in modular/VarDCT/filter paths and later writes through mutable subgrids.\n\n2. **Huge canvas plus tiny cropped frame**\n   This is the more practical “small payload, huge logical output” case. A bitstream-controlled frame crop can be tiny, but if the canvas/default requested region is huge, composition can allocate an output grid sized to the canvas/ROI at crates/jxl-render/src/blend.rs. That is bitstream frame cropping, not API crop. With a 32-bit target and a full requested image region whose area overflows, this can happen through ordinary `render_frame()`.\n\n### Impact\n\nOn 32-bit platforms this can cause out-of-bounds writes with attacker-controlled data when decoding a crafted JPEG XL image. This could allow arbitrary code execution.","aliases":["CVE-2026-52834","RUSTSEC-2026-0151"],"modified":"2026-07-02T21:11:21.211631010Z","published":"2026-07-02T20:45:59Z","database_specific":{"cwe_ids":["CWE-122","CWE-131","CWE-190"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-07-02T20:45:59Z","nvd_published_at":null},"references":[{"type":"WEB","url":"https://github.com/tirr-c/jxl-oxide/security/advisories/GHSA-5pmv-rx8r-wmv5"},{"type":"PACKAGE","url":"https://github.com/tirr-c/jxl-oxide"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2026-0151.html"}],"affected":[{"package":{"name":"jxl-grid","ecosystem":"crates.io","purl":"pkg:cargo/jxl-grid"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.6.2"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 0.6.1","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-5pmv-rx8r-wmv5/GHSA-5pmv-rx8r-wmv5.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:H"}]}