Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2025-12474— libjxl: Uninitialized memory read in decoder due to incorrect optimization in patch handling

Quick assessment

Affected
Google libjxl
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

libjxl是libjxl开源的一个 JPEG XL 图像格式参考实现。 libjxl存在安全漏洞,该漏洞源于特制文件可能导致解码器从未初始化内存读取像素数据,可能导致信息泄露。

AI Predicted 7.5 Difficulty: Moderate EPSS 0.10% · P1

Possible ATT&CK Techniques 1 AI

T1203 · Exploitation for Client Execution
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2025-12474

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
libjxl: Uninitialized memory read in decoder due to incorrect optimization in patch handling
Source: CVE Program / CVE List V5
Vulnerability Description
A specially-crafted file can cause libjxl's decoder to read pixel data from uninitialized (but allocated) memory. This can be done by causing the decoder to reference an outside-image-bound area in a subsequent patches. An incorrect optimization causes the decoder to omit populating those areas.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
对未经初始化资源的使用
Source: CVE Program / CVE List V5
Vulnerability Title
libjxl 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
libjxl是libjxl开源的一个 JPEG XL 图像格式参考实现。 libjxl存在安全漏洞,该漏洞源于特制文件可能导致解码器从未初始化内存读取像素数据,可能导致信息泄露。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Google libjxl 0.7 ~ 0.11.1 -

II. Public POCs for CVE-2025-12474

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-12474

登录查看更多情报信息。

Same Patch Batch · Google · 2026-02-11 · 14 CVEs total

CVE-2026-1669 Arbitrary File Read in Keras via HDF5 External Datasets
CVE-2026-2323 Google Chrome 安全漏洞
CVE-2026-2322 Google Chrome 安全漏洞
CVE-2026-2320 Google Chrome 安全漏洞
CVE-2026-2321 Google Chrome 资源管理错误漏洞
CVE-2026-2318 Google Chrome 安全漏洞
CVE-2026-2319 Google Chrome 安全漏洞
CVE-2026-2317 Google Chrome 安全漏洞
CVE-2026-2316 Google Chrome 安全漏洞
CVE-2026-2315 Google Chrome 安全漏洞
CVE-2026-2314 Google Chrome 安全漏洞
CVE-2026-2313 Google Chrome 资源管理错误漏洞
CVE-2026-1837 libjxl: Out-of-bounds write in grayscale color transformation when using LCMS2

IV. Related Vulnerabilities

V. Comments for CVE-2025-12474

No comments yet


Leave a comment