CVE-2021-28026: Buffer Overflow
Published Mar 5, 2021
·Updated
jpeg-xl v0.3.2 is affected by a heap buffer overflow in /lib/jxl/coefforder.cc ReadPermutation. When decoding a malicous jxl file using djxl, an attacker can trigger arbitrary code execution or a denial of service.
Affected Software
1 affected component
jpeg jpeg-xl=0.3.2
Event History
Mar 5, 2021
CVE Published
via MITRE·01:17 PM
Data Sourced
via MITRE·01:17 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-28026?
CVE-2021-28026 has a high severity due to the potential for arbitrary code execution or denial of service.
2
How do I fix CVE-2021-28026?
To mitigate CVE-2021-28026, upgrade to a newer version of jpeg-xl beyond version 0.3.2.
3
What is the vector of attack for CVE-2021-28026?
The attack vector for CVE-2021-28026 is through the decoding of a malicious jxl file using the djxl tool.
4
What type of vulnerability is CVE-2021-28026?
CVE-2021-28026 is classified as a heap buffer overflow vulnerability.
5
What software versions are affected by CVE-2021-28026?
CVE-2021-28026 affects jpeg-xl version 0.3.2.