Skip to content

fix(jpegxl): harden against corrupt input - #5378

Merged
lgritz merged 1 commit into
AcademySoftwareFoundation:mainfrom
lgritz:lg-jpegxl
Aug 14, 2026
Merged

fix(jpegxl): harden against corrupt input#5378
lgritz merged 1 commit into
AcademySoftwareFoundation:mainfrom
lgritz:lg-jpegxl

Conversation

@lgritz

@lgritz lgritz commented Aug 7, 2026

Copy link
Copy Markdown
Collaborator
  • Overflow protection for the out-buffer-size sanity check, which computed xsizeysizechannels*bits/8 as uint32 previously.
  • The result of m_io->read() was captured but never checked; a short read left the tail of the input buffer uninitialized and handed it to libjxl. Error out when the read is short.
  • If the decode loop reached JXL_DEC_SUCCESS with basic info but never requested an image-out buffer, m_buffer stayed null while open() returned success, so a later read_native_scanline() dereferenced null. Reject such files at open time.
  • Add a truncated-codestream test for jxl.

Assisted-by: Claude Code / Claude Opus 4.8

- Overflow protection for the out-buffer-size sanity check, which
  computed xsize*ysize*channels*bits/8 as uint32 previously.
- The result of m_io->read() was captured but never checked; a short read
  left the tail of the input buffer uninitialized and handed it to libjxl.
  Error out when the read is short.
- If the decode loop reached JXL_DEC_SUCCESS with basic info but never
  requested an image-out buffer, m_buffer stayed null while open()
  returned success, so a later read_native_scanline() dereferenced null.
  Reject such files at open time.
- Add a truncated-codestream test for jxl.

Assisted-by: Claude Code / Claude Opus 4.8

Signed-off-by: Larry Gritz <lg@larrygritz.com>
@lgritz
lgritz merged commit c7c1955 into AcademySoftwareFoundation:main Aug 14, 2026
30 checks passed
@lgritz
lgritz deleted the lg-jpegxl branch August 14, 2026 17:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants