{"schema_version":"1.9.0","id":"CVE-2024-11498","published":"2024-11-25T13:08:07.140Z","modified":"2026-08-12T03:51:26.173806442Z","related":["SUSE-SU-2024:4411-1","SUSE-SU-2026:1154-1","openSUSE-SU-2024:14531-1","openSUSE-SU-2024:14594-1","openSUSE-SU-2024:14600-1","openSUSE-SU-2025:0041-1","openSUSE-SU-2025:0139-1"],"summary":"Resource exhaustion via Stack overflow in libjxl","details":"There exists a stack buffer overflow in libjxl. A specifically-crafted file can cause the JPEG XL decoder to use large amounts of stack space (up to 256mb is possible, maybe 512mb), potentially exhausting the stack. An attacker can craft a file that will cause excessive memory usage. We recommend upgrading past commit 65fbec56bc578b6b6ee02a527be70787bbd053b0.","affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/libjxl/libjxl","events":[{"introduced":"0"},{"fixed":"aa2df30120b92078ab7b172fadf97dd7a937f51a"}],"database_specific":{"cpe":"cpe:2.3:a:libjxl_project:libjxl:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"0.8.4"}],"source":"CPE_RANGE"}}],"versions":["v0.8.3","v0.8.2","v0.8.1","v0.8.0","v0.8.0rc1","v0.7rc","v0.7-base","v0.8-snapshot","v0.6-base","v0.5-base","v0.3.7","v0.3.6","v0.3.5","v0.3.4","v0.3.3","v0.3.2","v0.3.1","v0.3.0","v0.3","v0.2.0","v0.2","v0.1.1","v0.1.0","v0.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-11498.json"}}],"references":[{"type":"WEB","url":"https://github.com/libjxl/libjxl/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/11xxx/CVE-2024-11498.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-11498"},{"type":"FIX","url":"https://github.com/libjxl/libjxl/pull/3943"}],"database_specific":{"cna_assigner":"Google","cwe_ids":["CWE-400"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/11xxx/CVE-2024-11498.json","unresolved_ranges":[{"extracted_events":[{"introduced":"0.11.0"},{"fixed":"65fbec56bc578b6b6ee02a527be70787bbd053b0"},{"introduced":"0.10.0-2"},{"fixed":"65fbec56bc578b6b6ee02a527be70787bbd053b0"},{"introduced":"0.9.0-3"},{"fixed":"65fbec56bc578b6b6ee02a527be70787bbd053b0"},{"introduced":"0.8.0-3"},{"fixed":"65fbec56bc578b6b6ee02a527be70787bbd053b0"},{"introduced":"0.7.0-1"},{"fixed":"65fbec56bc578b6b6ee02a527be70787bbd053b0"}],"source":"AFFECTED_FIELD"}]},"severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H"}]}