https://seclists.org/oss-sec/2026/q2/1052: CVE-2023-0645: libjxl/cjxl out-of-bounds ad in EXIF metadata parsing
Published Jun 29, 2026
·Updated
Affected Software
1 affected component
libjxl libjxl<0.8.1
Frequently Asked Questions
1
What is the severity of CVE-2023-0645?
CVE-2023-0645 has a critical severity rating with a CVSS score of 9.1.
2
How do I fix CVE-2023-0645?
To fix CVE-2023-0645, upgrade libjxl to version 0.8.1 or later.
3
What vulnerabilities does CVE-2023-0645 introduce?
CVE-2023-0645 introduces an out-of-bounds read vulnerability during EXIF metadata parsing in libjxl.
4
Which versions of libjxl are affected by CVE-2023-0645?
CVE-2023-0645 affects all versions of libjxl before 0.8.1.
5
What impact can CVE-2023-0645 have on systems?
The impact of CVE-2023-0645 can include potential information disclosure due to the out-of-bounds read vulnerability.