
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2022-34000 is a vulnerability discovered in libjxl version 0.6.1, specifically involving an assertion failure in the LowMemoryRenderPipeline::Init() function located in renderpipeline/lowmemoryrenderpipeline.cc. The vulnerability was disclosed on June 19, 2022, affecting the JPEG XL image format reference implementation (NVD, MITRE).
The vulnerability stems from an unnecessary assertion in the LowMemoryRenderPipeline::Init function. The assertion failure occurs at line 312 of lowmemoryrenderpipeline.cc with the condition 'firstimagedimstage == stages.size() || i >= firstimagedimstage' (GitHub Issue).
When exploited, this vulnerability can result in a denial of service (DoS) attack against the libjxl process through the use of specially crafted input files (Gentoo Security).
The vulnerability has been fixed in libjxl version 0.7.0_pre20220825 and later releases. Users are advised to upgrade to the latest version to mitigate this security issue. For Debian systems, fixed versions are available in bookworm (0.7.0-10), trixie (0.10.4-2), and sid (0.11.1-3) releases (Debian Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."