Logo
vulnerabilityCVE-2025-12474
Name
CVE-2025-12474
Source
NVD ( link)Debian ( link)
Description
A specially-crafted file can cause libjxl's decoder to read pixel data from uninitialized (but allocated) memory. This can be done by causing the decoder to reference an outside-image-bound area in a subsequent patches. An incorrect optimization causes the decoder to omit populating those areas.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
libjxl
Not Affected

Vulnerability Ratings#


2.3
CVSSv4
4.4
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
0.11.2
Not Affected
buildroot
master
0.11.2
Not Affected
yocto
scarthgap
0.10.5
Not Affected