Skip to main content
EPSS 0.1%top 97%

CVE-2026-52834: CWE-122: Heap-based Buffer Overflow in tirr-c jxl-oxide

0
High
Published: 08/19/2026 (08/19/2026, 14:55:32 UTC)
Source: GCVE Database
Vendor/Project: tirr-c
Product: jxl-oxide

Description

jxl-oxide is a pure Rust implementation of a JPEG XL decoder. Prior to jxl-grid 0.6.2, decoding a crafted JPEG XL image on a 32-bit platform can overflow length calculations in AlignedGrid::with_alloc_tracker and related grid and subgrid arithmetic. A 65536 x 65536 frame can pass the frame-area limit while overflowing the usize element count, causing modular, VarDCT, or filter rendering paths to allocate a backing buffer smaller than the logical grid. A tiny bitstream-controlled cropped frame combined with a huge canvas or requested region can also reach the vulnerable composition path in crates/jxl-render/src/blend.rs through ordinary render_frame(). Later mutable subgrid and raw-pointer operations can then perform attacker-controlled out-of-bounds writes, causing memory corruption, denial of service, or arbitrary code execution. This issue is fixed in jxl-grid version 0.6.2.

CVSS v3.1

Score 7.3high

Attack Vector
Local
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
High
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:H

Affected software

crates.ioghsa
jxl-grid
Affected versions
<0.6.2

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/21/2026, 11:10:25 UTC

Technical Analysis

The vulnerability in jxl-oxide arises from an integer overflow in AlignedGrid::with_alloc_tracker and related grid arithmetic on 32-bit platforms when decoding malicious JPEG XL images. Specifically, a large frame size (e.g., 65536 x 65536) can bypass frame-area limits but overflow the usize element count, resulting in undersized buffer allocation. Additionally, a crafted bitstream with a cropped frame and large canvas can trigger the vulnerable composition path in blend.rs. Subsequent mutable subgrid and raw-pointer operations perform out-of-bounds writes controlled by the attacker, leading to memory corruption, denial of service, or arbitrary code execution. The issue is resolved in jxl-grid 0.6.2.

Potential Impact

Successful exploitation can lead to memory corruption, denial of service, or arbitrary code execution on affected 32-bit platforms running vulnerable versions of jxl-oxide. The vulnerability affects confidentiality, integrity, and availability as indicated by the CVSS vector (C:L/I:L/A:H).

Mitigation Recommendations

Upgrade to jxl-grid version 0.6.2 or later, which contains the official fix for this vulnerability. No other mitigations are indicated by the vendor advisory.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-5pmv-rx8r-wmv5
Osv Schema Version
1.4.0
Aliases
["CVE-2026-52834"]
Ecosystems
["crates.io"]
Database Specific Severity
HIGH
Cvss Version
3.1

Threat ID: 6a46ecae27e9c7971943b8e5

Added to database: 07/02/2026, 22:56:46 UTC

Last enriched: 08/21/2026, 11:10:25 UTC

Last updated: 09/14/2026, 22:01:35 UTC

Views: 122

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses