{"id":"USN-8146-1","summary":"jpeg-xl vulnerability","details":"Daniel Novomeský discovered that libjxl did not properly manage memory when\ndecoding certain files. An attacker could use this issue to cause\nlibjxl to crash, resulting in denial of service, or possibly execute\narbitrary code.","modified":"2026-06-30T18:15:39.034761213Z","published":"2026-04-02T19:09:19Z","related":["UBUNTU-CVE-2026-1837"],"upstream":["UBUNTU-CVE-2026-1837"],"references":[{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-8146-1"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-1837"}],"affected":[{"package":{"name":"jpeg-xl","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/jpeg-xl?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.11.1-6ubuntu1.1"}]}],"versions":["0.11.1-4","0.11.1-6ubuntu1"],"ecosystem_specific":{"binaries":[{"binary_name":"libjpegxl-java","binary_version":"0.11.1-6ubuntu1.1"},{"binary_version":"0.11.1-6ubuntu1.1","binary_name":"libjxl-devtools"},{"binary_name":"libjxl-gdk-pixbuf","binary_version":"0.11.1-6ubuntu1.1"},{"binary_version":"0.11.1-6ubuntu1.1","binary_name":"libjxl-tools"},{"binary_name":"libjxl0.11","binary_version":"0.11.1-6ubuntu1.1"}],"availability":"No subscription required"},"database_specific":{"cves_map":{"ecosystem":"Ubuntu:25.10","cves":[{"severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-1837"}]},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8146-1.json"}}],"schema_version":"1.7.5"}