{"id":"GHSA-2v8p-fqpx-2q3w","aliases":[],"url":"https://o3.security/vulnerability/GHSA-2v8p-fqpx-2q3w","summary":"jxl-oxide: integer subtraction overflow panic in cluster_from_table via crafted JXL input (DoS)","details":"### Summary\nLogic bug in `decode_simple_table_slow` may cause integer arithmetic overflow when decoding Modular image with certain kind of MA tree, which may panic with `overflow-checks` enabled.\n\n### Impact\nDenial of service: any application passing untrusted JXL data to `JxlImage::render_frame` (or equivalent) can be\ncrashed. Affects all builds with overflow checks enabled, which includes debug builds and any release build\nthat sets `overflow-checks = true` in Cargo.toml or `[profile.*]`.\n\nNo memory corruption is possible — the panic fires before any unsafe code is reached.","published":"2026-07-02T20:44:57Z","modified":"2026-07-02T21:00:18.159260333Z","cvss":{"score":6.2,"severity":"MEDIUM","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"crates.io","name":"jxl-modular","fixedVersion":"0.11.3"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/tirr-c/jxl-oxide/security/advisories/GHSA-2v8p-fqpx-2q3w"},{"type":"PACKAGE","url":"https://github.com/tirr-c/jxl-oxide"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-02T21:00:18.159260333Z"}}