Bugzilla – Bug 1212492
VUL-0: CVE-2023-35790: libjxl: integer underflow bug in patch decoding
Last modified: 2023-06-29 19:05:30 UTC
Security: Fix an integer underflow bug in patch decoding (#2551). https://github.com/libjxl/libjxl/releases/tag/v0.8.2 https://github.com/libjxl/libjxl/pull/2551
Fixed in openSUSE:Factory adding jengelh for visibility
This is an autogenerated message for OBS integration: This bug (1212492) was mentioned in https://build.opensuse.org/request/show/1093764 Backports:SLE-15-SP5 / libjxl
(i put CVE and bug into the patchinfo for 15-sp5)
openSUSE-SU-2023:0161-1: An update that fixes one vulnerability is now available.\n\nCategory: security (moderate)\nBug References: 1212492\nCVE References: CVE-2023-35790\nJIRA References: \nSources used:\nopenSUSE Backports SLE-15-SP5 (src): libjxl-0.8.2-bp155.2.3.1\n\n