Assertion Failure in LowMemoryRenderPipeline in libjxl by Google
CVE-2022-34000

6.5MEDIUM

Key Information:

Status
Vendor
CVE Published:
19 June 2022

What is CVE-2022-34000?

The libjxl version 0.6.1 exhibits an assertion failure within the LowMemoryRenderPipeline::Init() method located in the render_pipeline/low_memory_render_pipeline.cc file. This flaw could potentially lead to integrity issues or service disruption during the processing of images, making it essential for users and developers to address this vulnerability promptly.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.