CVE-2024-11498 - CVE House
Back to Database
Status published Medium CVE-2024-11498

Resource exhaustion via Stack overflow in libjxl

Vulnerability Description

There exists a stack buffer overflow in libjxl. A specifically-crafted file can cause the JPEG XL decoder to use large amounts of stack space (up to 256mb is possible, maybe 512mb), potentially exhausting the stack. An attacker can craft a file that will cause excessive memory usage. We recommend upgrading past commit 65fbec56bc578b6b6ee02a527be70787bbd053b0.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-11498

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

libjxl
Vulnerable Versions:
0.11.0, 0.10.0-2, 0.9.0-3, 0.8.0-3, 0.7.0-1

Timeline

Official Publish: November 25th, 2024
Last Modified: November 25th, 2024
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)