Skip to content

fix(jpegxl): harden against corrupt input - #5378

Open
lgritz wants to merge 1 commit into
AcademySoftwareFoundation:mainfrom
lgritz:lg-jpegxl
Open

fix(jpegxl): harden against corrupt input#5378
lgritz wants to merge 1 commit into
AcademySoftwareFoundation:mainfrom
lgritz:lg-jpegxl

Conversation

@lgritz

@lgritz lgritz commented Aug 7, 2026

Copy link
Copy Markdown
Collaborator
  • Overflow protection for the out-buffer-size sanity check, which computed xsizeysizechannels*bits/8 as uint32 previously.
  • The result of m_io->read() was captured but never checked; a short read left the tail of the input buffer uninitialized and handed it to libjxl. Error out when the read is short.
  • If the decode loop reached JXL_DEC_SUCCESS with basic info but never requested an image-out buffer, m_buffer stayed null while open() returned success, so a later read_native_scanline() dereferenced null. Reject such files at open time.
  • Add a truncated-codestream test for jxl.

Assisted-by: Claude Code / Claude Opus 4.8

- Overflow protection for the out-buffer-size sanity check, which
  computed xsize*ysize*channels*bits/8 as uint32 previously.
- The result of m_io->read() was captured but never checked; a short read
  left the tail of the input buffer uninitialized and handed it to libjxl.
  Error out when the read is short.
- If the decode loop reached JXL_DEC_SUCCESS with basic info but never
  requested an image-out buffer, m_buffer stayed null while open()
  returned success, so a later read_native_scanline() dereferenced null.
  Reject such files at open time.
- Add a truncated-codestream test for jxl.

Assisted-by: Claude Code / Claude Opus 4.8

Signed-off-by: Larry Gritz <lg@larrygritz.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant