PatchSiren

tirr-c CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH tirr-c CVE published 2026-08-19

CVE-2026-52834

A crafted JPEG XL image can cause an integer overflow in jxl-oxide, leading to memory corruption, denial of service, or arbitrary code execution. This issue is fixed in jxl-grid version 0.6.2. The vulnerability arises from decoding a crafted JPEG XL image on a 32-bit platform, which can overflow length calculations in AlignedGrid::with_alloc_tracker and related grid and subgrid arithmetic. A 65536 x 65536 [truncated]