CVE-2026-52834: CWE-122: Heap-based Buffer Overflow in tirr-c jxl-oxide
jxl-oxide is a pure Rust implementation of a JPEG XL decoder. Prior to jxl-grid 0.6.2, decoding a crafted JPEG XL image on a 32-bit platform can overflow length calculations in AlignedGrid::with_alloc_tracker and related grid and subgrid arithmetic. A 65536 x 65536 frame can pass the frame-area limit while overflowing the usize element count, causing modular, VarDCT, or filter rendering paths to allocate a backing buffer smaller than the logical grid. A tiny bitstream-controlled cropped frame combined with a huge canvas or requested region can also reach the vulnerable composition path in crates/jxl-render/src/blend.rs through ordinary render_frame(). Later mutable subgrid and raw-pointer operations can then perform attacker-controlled out-of-bounds writes, causing memory corruption, denial of service, or arbitrary code execution. This issue is fixed in jxl-grid version 0.6.2.
AI Analysis
Technical Summary
The vulnerability in jxl-oxide arises from an integer overflow in AlignedGrid::with_alloc_tracker and related grid arithmetic on 32-bit platforms when decoding malicious JPEG XL images. Specifically, a large frame size (e.g., 65536 x 65536) can bypass frame-area limits but overflow the usize element count, resulting in undersized buffer allocation. Additionally, a crafted bitstream with a cropped frame and large canvas can trigger the vulnerable composition path in blend.rs. Subsequent mutable subgrid and raw-pointer operations perform out-of-bounds writes controlled by the attacker, leading to memory corruption, denial of service, or arbitrary code execution. The issue is resolved in jxl-grid 0.6.2.
Potential Impact
Successful exploitation can lead to memory corruption, denial of service, or arbitrary code execution on affected 32-bit platforms running vulnerable versions of jxl-oxide. The vulnerability affects confidentiality, integrity, and availability as indicated by the CVSS vector (C:L/I:L/A:H).
Mitigation Recommendations
Upgrade to jxl-grid version 0.6.2 or later, which contains the official fix for this vulnerability. No other mitigations are indicated by the vendor advisory.
CVE-2026-52834: CWE-122: Heap-based Buffer Overflow in tirr-c jxl-oxide
Description
jxl-oxide is a pure Rust implementation of a JPEG XL decoder. Prior to jxl-grid 0.6.2, decoding a crafted JPEG XL image on a 32-bit platform can overflow length calculations in AlignedGrid::with_alloc_tracker and related grid and subgrid arithmetic. A 65536 x 65536 frame can pass the frame-area limit while overflowing the usize element count, causing modular, VarDCT, or filter rendering paths to allocate a backing buffer smaller than the logical grid. A tiny bitstream-controlled cropped frame combined with a huge canvas or requested region can also reach the vulnerable composition path in crates/jxl-render/src/blend.rs through ordinary render_frame(). Later mutable subgrid and raw-pointer operations can then perform attacker-controlled out-of-bounds writes, causing memory corruption, denial of service, or arbitrary code execution. This issue is fixed in jxl-grid version 0.6.2.
CVSS v3.1
Score 7.3high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in jxl-oxide arises from an integer overflow in AlignedGrid::with_alloc_tracker and related grid arithmetic on 32-bit platforms when decoding malicious JPEG XL images. Specifically, a large frame size (e.g., 65536 x 65536) can bypass frame-area limits but overflow the usize element count, resulting in undersized buffer allocation. Additionally, a crafted bitstream with a cropped frame and large canvas can trigger the vulnerable composition path in blend.rs. Subsequent mutable subgrid and raw-pointer operations perform out-of-bounds writes controlled by the attacker, leading to memory corruption, denial of service, or arbitrary code execution. The issue is resolved in jxl-grid 0.6.2.
Potential Impact
Successful exploitation can lead to memory corruption, denial of service, or arbitrary code execution on affected 32-bit platforms running vulnerable versions of jxl-oxide. The vulnerability affects confidentiality, integrity, and availability as indicated by the CVSS vector (C:L/I:L/A:H).
Mitigation Recommendations
Upgrade to jxl-grid version 0.6.2 or later, which contains the official fix for this vulnerability. No other mitigations are indicated by the vendor advisory.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-5pmv-rx8r-wmv5
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-52834"]
- Ecosystems
- ["crates.io"]
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
Threat ID: 6a46ecae27e9c7971943b8e5
Added to database: 07/02/2026, 22:56:46 UTC
Last enriched: 08/21/2026, 11:10:25 UTC
Last updated: 09/14/2026, 22:01:35 UTC
Views: 122
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.