CVE-2025-70103: Heap-based Buffer Overflow in libjxl/cjxl via jxl::extras::DecodeImagePNM on crafted PBM file
Published May 27, 2026
·Updated
Heap buffer overflow vulnerability in libjxl 0.12.0 via crafted PBM images to the jxl::extras::DecodeImagePNM function in file lib/extras/dec/pnm.cc.
Affected Software
2 affected components
libjxl libjxl=0.12.0
debian/jpeg-xl<=0.7.0-10+deb12u1, <=0.11.2-0.1~deb13u1, <=0.11.2-5
Event History
May 27, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeakness
Jun 8, 2026
Data Sourced
via Debian·02:04 PM
DescriptionAffected Software
Data Sourced
via Launchpad·02:04 PM
Description
Jun 9, 2026
Data Sourced
via Ubuntu·02:04 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-70103?
The severity of CVE-2025-70103 is rated high with a CVSS score of 7.3.
2
How do I fix CVE-2025-70103?
To fix CVE-2025-70103, upgrade to the latest version of libjxl where this vulnerability is addressed.
3
What type of vulnerability is CVE-2025-70103?
CVE-2025-70103 is a heap-based buffer overflow vulnerability.
4
What software is affected by CVE-2025-70103?
CVE-2025-70103 affects libjxl version 0.12.0.
5
What is the impact of exploiting CVE-2025-70103?
Exploiting CVE-2025-70103 may lead to potential crashes and unauthorized access to memory.