HIGH
tirr-c
CVE published 2026-08-19
CVE-2026-52834
A crafted JPEG XL image can cause an integer overflow in jxl-oxide, leading to memory corruption, denial of service, or arbitrary code execution. This issue is fixed in jxl-grid version 0.6.2. The vulnerability arises from decoding a crafted JPEG XL image on a 32-bit platform, which can overflow length calculations in AlignedGrid::with_alloc_tracker and related grid and subgrid arithmetic. A 65536 x 65536 [truncated]