#1138575 jpeg-xl: CVE-2025-70103

Package:
src:jpeg-xl
Source:
src:jpeg-xl
Submitter:
Salvatore Bonaccorso
Date:
2026-08-22 19:51:02 UTC
Severity:
normal
Tags:
#1138575#5
Date:
2026-05-31 19:07:39 UTC
From:
To:
Hi,

The following vulnerability was published for jpeg-xl.

CVE-2025-70103[0]:
| Heap buffer overflow vulnerability in libjxl 0.12.0 via crafted PBM
| images to the jxl::extras::DecodeImagePNM function in file
| lib/extras/dec/pnm.cc.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2025-70103
https://www.cve.org/CVERecord?id=CVE-2025-70103
[1] https://github.com/libjxl/libjxl/issues/4337
[2] https://www.openwall.com/lists/oss-security/2026/05/30/7
[3] https://github.com/libjxl/libjxl/pull/4380

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1138575#10
Date:
2026-06-01 03:52:41 UTC
From:
To:
Hi,

在 2026/6/1 03:07, Salvatore Bonaccorso 写道:

The libjxl upstream is not release version 0.12.0 now,
why record this CVE on un-release version?

Is it should record on the released version 0.11.2 ?

Regards,

#1138575#17
Date:
2026-06-13 13:53:57 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
jpeg-xl, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1138575@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Moritz Mühlenhoff <jmm@debian.org> (supplier of updated jpeg-xl package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Thu, 11 Jun 2026 20:15:43 +0200
Source: jpeg-xl
Architecture: source
Version: 0.11.2-0.1~deb13u2
Distribution: trixie-security
Urgency: medium
Maintainer: Debian PhotoTools Maintainers <pkg-phototools-devel@lists.alioth.debian.org>
Changed-By: Moritz Mühlenhoff <jmm@debian.org>
Closes: 1138575
Changes:
 jpeg-xl (0.11.2-0.1~deb13u2) trixie-security; urgency=medium
 .
   * CVE-2025-70103 (Closes: #1138575)
Checksums-Sha1:
 2bf78fcbfdabbc109272b48f6339972b1f5fa968 3212 jpeg-xl_0.11.2-0.1~deb13u2.dsc
 2acaf75909eea67cc7d861a9a918733d5f630db8 1882762 jpeg-xl_0.11.2.orig.tar.gz
 46f0eac9c10525dea68fb8f650e9ef216dbc5e11 23848 jpeg-xl_0.11.2-0.1~deb13u2.debian.tar.xz
 7892ed6b9fa3e2e9f6eca071ee979e0983db9d7d 18696 jpeg-xl_0.11.2-0.1~deb13u2_amd64.buildinfo
Checksums-Sha256:
 b978be4319975d73759f0737ba6935fad4f4330802835d6d9298a455c2581363 3212 jpeg-xl_0.11.2-0.1~deb13u2.dsc
 ab38928f7f6248e2a98cc184956021acb927b16a0dee71b4d260dc040a4320ea 1882762 jpeg-xl_0.11.2.orig.tar.gz
 54192375c3ff271f395b815a8ea111a5f632f5db8966baeda9dabedbc86ea2d4 23848 jpeg-xl_0.11.2-0.1~deb13u2.debian.tar.xz
 059d6b6c1da2042bff58873b776a006c72b2b5dc60aed33cb043d94b06a74705 18696 jpeg-xl_0.11.2-0.1~deb13u2_amd64.buildinfo
Files:
 da3a6fc6eb6052c7b45cabbe791917ec 3212 graphics optional jpeg-xl_0.11.2-0.1~deb13u2.dsc
 eda39db6e7a58b73be9124381862b9d1 1882762 graphics optional jpeg-xl_0.11.2.orig.tar.gz
 5f72e49457b31a5ef83eb4dc87a52ec3 23848 graphics optional jpeg-xl_0.11.2-0.1~deb13u2.debian.tar.xz
 d724a9a49d08f5b8298298b3d58a560e 18696 graphics optional jpeg-xl_0.11.2-0.1~deb13u2_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmorA24ACgkQEMKTtsN8
TjbzYA/+Npbp9/Fe3ZT9AiugvaZOQxXvRTm5JxX3YgRhU202+LXIYDyQxLTXT7sj
S2vBYezTNM88v3Iku/JzHPndAFUUANvnT8krstaND42cxkIKj5crpGAHr9Yz1u5m
DQSCtvxQ/s+CY/5400iUqeNzP7cMLJERi1IUZ19vD4ej4Gpda6RzKP9kRzj3/7pT
8pm8XmVe0Rkpox6SZjPukoWPXtugvxD23YJSkiaGdKihfv+MstAiXVS/ezhD1RzJ
z2LALgwZauW2+9KJpLB831CNdP7JVIADQV8Q2UzirFM6WW+uodUkUmIgjFNBYpTx
HOvY8jH1LpojV5RrUPL7yBYNTvp+ocHL/CZ/hJm/EYxcREhwMWVMEHw4h/uzzG2u
1s0ewuEpWmacGfmgg53Fly1npwnGVNfC3sxXVJC5tK3JEDjcmWQ40IYcA4z4AGUm
sTBNC3QxEwUDJQW59nIu5y6MCGsJXPHLz2b0rJytkMeolPfab+ilAKocWFbB+2G6
6G4lPFrSYhH1+PjM6AyBnF2daQmhN8DflQHiMnAvY1kLeCINFWyJUnrkM5rSeNrQ
Dv4bISwANpaU2go+sDCqtUkCka3ax3EZo6TmAdN++GirtOZPzuklz7HuTFainhJT
ID92SawSayo7sz5Wd7anAaOcIlS1P6yswkpH2P3IQT/N3hmJ5Bs=
=1Q/G
-----END PGP SIGNATURE-----

#1138575#28
Date:
2026-08-13 13:56:08 UTC
From:
To:
Dear maintainer,

I've prepared an NMU for jpeg-xl (versioned as 0.11.2-5.1) and uploaded
it to DELAYED/7. Please feel free to tell me if I should cancel it.

cu
Adrian

#1138575#37
Date:
2026-08-22 19:49:47 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
jpeg-xl, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1138575@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Adrian Bunk <bunk@debian.org> (supplier of updated jpeg-xl package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Thu, 13 Aug 2026 16:09:49 +0300
Source: jpeg-xl
Architecture: source
Version: 0.11.2-5.1
Distribution: unstable
Urgency: medium
Maintainer: Debian PhotoTools Maintainers <pkg-phototools-devel@lists.alioth.debian.org>
Changed-By: Adrian Bunk <bunk@debian.org>
Closes: 1138575 1142476
Changes:
 jpeg-xl (0.11.2-5.1) unstable; urgency=medium
 .
   * Non-maintainer upload.
   * CVE-2025-70103: Buffer overflow in PNM decoder
     (Closes: #1138575)
   * CVE-2026-52584: Buffer overflow in APNG decoder
     (Closes: #1142476)
   * Backport upstream fix for FTBFS on x32.
Checksums-Sha1:
 0287faf48e51f8478358b55f375240abbe2b7a23 3215 jpeg-xl_0.11.2-5.1.dsc
 57ef93c50262422f1e9d2d79be1ed624bed5b79b 20680 jpeg-xl_0.11.2-5.1.debian.tar.xz
Checksums-Sha256:
 547a1c75f467336b82c7178bb2390a3df5d68eddffa77ca7679754a5c3956f89 3215 jpeg-xl_0.11.2-5.1.dsc
 45b2b711b09fc3d6362cb2604befcbcbd8f0ba5937e65ad88163a1c8c66bc0dd 20680 jpeg-xl_0.11.2-5.1.debian.tar.xz
Files:
 4b2da2e56f9179e2e4f2ebb031333c50 3215 graphics optional jpeg-xl_0.11.2-5.1.dsc
 2bad471218d2c1fce5d4a07d1e9d2a1a 20680 graphics optional jpeg-xl_0.11.2-5.1.debian.tar.xz
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEOvp1f6xuoR0v9F3wiNJCh6LYmLEFAmp9zNQACgkQiNJCh6LY
mLH8rQ/+KGA+X+q8fwWqwiENJ1fI0JJMflfLZhy24mwvjD0NQ6Bg5bPcClO8xN+4
GePwVutuSSLjntTcPmFX2x0GPw81vYiXnjDJy8M1HcWlaxuNGLCdGprcsZfQwJ3G
V8w/am9zwPNaayc5D7NnJ55RO0C0wgsvKL2VwJFHDgswQpB2nSPMwNm4s4RYQLah
SVhprreCfOrnEsMR6tselC784WlG6LtykdvoU2gqGVz98h82zE4h7/MqMTJsqcew
gNiZcbWij0FGIcYsCeV/tJlrs42wtx71D2zvGZPumBrQL15Zp3jeG1CTOb+9ofMi
Tz4b8hFHcH5q3vJ8bXroiezgKx8Je8oQQ8VKlEjCDbKUJouquqgO3plNA/Drx+5B
fNWyPU6l/Jq2RRExxUhGMq7EZHA7jvOp1Mq8Lz5DENP1i5rXupQta/MCc7VwmlgJ
iE5neKfj3DA+58IMtZ4jnciG2bqM+eB6IvYNp1VOcs8JdrWvhVJtoOHf8dDTVJwZ
UEhh9tkbQZxcHDpWGD8+IujIWxU/JAX20Ns5/z2FeGeX9xay4pjgSz0WFinv0YnE
Mkyo4/kLfoBzfI0ehBl3BfG7r4ImQC1nG7xyLVucxM2vSRkyLie/SYfyCs+nTnah
LxtiH/Cz20tMGtglV4CsVdMsCE2qukbgY+Q+EITnuGXGiucT08E=
=w1Yt
-----END PGP SIGNATURE-----