Debian Package Tracker
Register | Log in
Subscribe

jpeg-xl

Choose email to subscribe with

general
  • source: jpeg-xl (main)
  • version: 0.11.1-4
  • maintainer: Debian PhotoTools Maintainers (archive) (DMD)
  • uploaders: Mathieu Malaterre [DMD]
  • arch: all any
  • std-ver: 4.7.0
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • stable: 0.7.0-10
  • testing: 0.11.1-4
  • unstable: 0.11.1-4
versioned links
  • 0.7.0-10: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 0.11.1-4: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • jpeg-xl-doc
  • libjpegxl-java
  • libjxl-dev
  • libjxl-devtools
  • libjxl-gdk-pixbuf
  • libjxl-tools
  • libjxl0.11
action needed
4 security issues in bookworm high

There are 4 open security issues in bookworm.

1 important issue:
  • CVE-2024-11403: There exists an out of bounds read/write in LibJXL versions prior to commit 9cc451b91b74ba470fd72bd48c121e9f33d24c99. The JPEG decoder used by the JPEG XL encoder when doing JPEG recompression (i.e. if using JxlEncoderAddJPEGFrame on untrusted input) does not properly check bounds in the presence of incomplete codes. This could lead to an out-of-bounds write. In jpegli which is released as part of the same project, the same vulnerability is present. However, the relevant buffer is part of a bigger structure, and the code makes no assumptions on the values that could be overwritten. The issue could however cause jpegli to read uninitialised memory, or addresses of functions.
3 issues left for the package maintainer to handle:
  • CVE-2023-0645: (needs triaging) An out of bounds read exists in libjxl. An attacker using a specifically crafted file could cause an out of bounds read in the exif handler. We recommend upgrading to version 0.8.1 or past commit  https://github.com/libjxl/libjxl/pull/2101/commits/d95b050c1822a5b1ede9e0dc937e43fca1b10159 https://github.com/libjxl/libjxl/pull/2101/commits/d95b050c1822a5b1ede9e0dc937e43fca1b10159
  • CVE-2023-35790: (needs triaging) An issue was discovered in dec_patch_dictionary.cc in libjxl before 0.8.2. An integer underflow in patch decoding can lead to a denial of service, such as an infinite loop.
  • CVE-2024-11498: (needs triaging) There exists a stack buffer overflow in libjxl. A specifically-crafted file can cause the JPEG XL decoder to use large amounts of stack space (up to 256mb is possible, maybe 512mb), potentially exhausting the stack. An attacker can craft a file that will cause excessive memory usage. We recommend upgrading past commit 65fbec56bc578b6b6ee02a527be70787bbd053b0.

You can find information about how to handle these issues in the security team's documentation.

Created: 2023-06-10 Last update: 2025-03-26 04:32
lintian reports 2 errors and 1 warning high
Lintian reports 2 errors and 1 warning about this package. You should make the package lintian clean getting rid of them.
Created: 2025-03-21 Last update: 2025-03-21 09:02
Depends on packages which need a new maintainer normal
The packages that jpeg-xl depends on which need a new maintainer are:
  • docbook-xml (#802368)
    • Build-Depends: docbook-xml
Created: 2023-09-01 Last update: 2025-05-18 06:30
Multiarch hinter reports 1 issue(s) normal
There are issues with the multiarch metadata for this package.
  • libjpegxl-java could be marked Multi-Arch: same
Created: 2025-03-25 Last update: 2025-05-18 03:31
Does not build reproducibly during testing normal
A package building reproducibly enables third parties to verify that the source matches the distributed binaries. It has been identified that this source package produced different results, failed to build or had other issues in a test environment. Please read about how to improve the situation!
Created: 2024-10-09 Last update: 2025-05-18 03:30
3 new commits since last upload, is it time to release? normal
vcswatch reports that this package seems to have new commits in its VCS but has not yet updated debian/changelog. You should consider updating the Debian changelog and uploading this new version into the archive.

Here are the relevant commit logs:
commit 820ff6b2e428de71de5464665485e6a0233ebc57
Merge: c350a24 862b7dd
Author: Mathieu Malaterre <malat@debian.org>
Date:   Fri Mar 21 12:15:35 2025 +0100

    Merge branch 'debian/experimental'

commit c350a2459794f8b71ce65b3d5de1c83ed227759d
Merge: 64fbc92 a0c615e
Author: Mathieu Malaterre <malat@debian.org>
Date:   Thu Feb 6 07:16:05 2025 +0000

    Merge branch 'powerpc-gcc-14-restrict' into 'master'
    
    d/{control,rules}: use gcc-13 on powerpc and ppc64
    
    See merge request debian-phototools-team/libjxl!11

commit a0c615e7991a3e1a515890cc69ccb58cb3503dee
Author: Sean McGovern <gseanmcg@gmail.com>
Date:   Mon Jan 6 23:14:13 2025 -0500

    d/{control,rules}: use gcc-13 on powerpc and ppc64
Created: 2024-07-06 Last update: 2025-05-15 13:05
debian/patches: 2 patches to forward upstream low

Among the 5 debian patches available in version 0.11.1-4 of the package, we noticed the following issues:

  • 2 patches where the metadata indicates that the patch has not yet been forwarded upstream. You should either forward the patch upstream or update the metadata to document its real status.
Created: 2023-02-26 Last update: 2025-03-21 06:30
Build log checks report 1 warning low
Build log checks report 1 warning
Created: 2024-10-31 Last update: 2024-10-31 11:30
Standards version of the package is outdated. wishlist
The package should be updated to follow the last version of Debian Policy (Standards-Version 4.7.2 instead of 4.7.0).
Created: 2025-02-21 Last update: 2025-03-20 21:28
news
[rss feed]
  • [2025-03-26] jpeg-xl 0.11.1-4 MIGRATED to testing (Debian testing watch)
  • [2025-03-20] Accepted jpeg-xl 0.11.1-4 (source) into unstable (Jeremy Bícha) (signed by: Jeremy Bicha)
  • [2025-03-20] jpeg-xl 0.11.1-3 MIGRATED to testing (Debian testing watch)
  • [2025-03-15] Accepted jpeg-xl 0.11.1-3 (source) into unstable (Jeremy Bícha) (signed by: Jeremy Bicha)
  • [2025-03-14] Accepted jpeg-xl 0.11.1-2 (source) into experimental (Jeremy Bícha) (signed by: Jeremy Bicha)
  • [2025-02-08] Accepted jpeg-xl 0.11.1-1 (source all amd64) into experimental (Debian FTP Masters) (signed by: Mathieu Malaterre)
  • [2024-12-29] jpeg-xl 0.10.4-2 MIGRATED to testing (Debian testing watch)
  • [2024-12-26] Accepted jpeg-xl 0.10.4-2 (source) into unstable (Jeremy Bícha) (signed by: Jeremy Bicha)
  • [2024-12-17] Accepted jpeg-xl 0.10.4-1 (source) into experimental (Jeremy Bícha) (signed by: Jeremy Bicha)
  • [2024-09-27] Accepted jpeg-xl 0.10.3-5 (source) into experimental (Mathieu Malaterre)
  • [2024-07-23] Accepted jpeg-xl 0.10.3-4 (source) into experimental (Mathieu Malaterre)
  • [2024-07-21] Accepted jpeg-xl 0.10.3-3 (source) into experimental (Mathieu Malaterre)
  • [2024-07-21] Accepted jpeg-xl 0.10.3-2 (source all amd64) into experimental (Debian FTP Masters) (signed by: Mathieu Malaterre)
  • [2024-07-07] jpeg-xl 0.9.2-10 MIGRATED to testing (Debian testing watch)
  • [2024-07-06] Accepted jpeg-xl 0.10.3-1 (source all amd64) into experimental (Debian FTP Masters) (signed by: Mathieu Malaterre)
  • [2024-07-05] Accepted jpeg-xl 0.9.2-10 (source) into unstable (Mathieu Malaterre)
  • [2024-07-01] jpeg-xl 0.9.2-9 MIGRATED to testing (Debian testing watch)
  • [2024-06-26] Accepted jpeg-xl 0.9.2-9 (source) into unstable (Mathieu Malaterre)
  • [2024-06-12] Accepted jpeg-xl 0.9.2-8 (source) into experimental (Mathieu Malaterre)
  • [2024-06-11] Accepted jpeg-xl 0.9.2-7 (source) into experimental (Mathieu Malaterre)
  • [2024-06-10] Accepted jpeg-xl 0.9.2-6 (source) into experimental (Mathieu Malaterre)
  • [2024-06-07] Accepted jpeg-xl 0.9.2-5 (source) into experimental (Mathieu Malaterre)
  • [2024-06-07] Accepted jpeg-xl 0.9.2-4 (source) into experimental (Mathieu Malaterre)
  • [2024-06-07] Accepted jpeg-xl 0.9.2-3 (source) into experimental (Mathieu Malaterre)
  • [2024-06-04] Accepted jpeg-xl 0.9.2-2 (source all i386) into experimental (Debian FTP Masters) (signed by: Mathieu Malaterre)
  • [2024-06-03] Accepted jpeg-xl 0.9.2-1 (source all i386) into experimental (Debian FTP Masters) (signed by: Mathieu Malaterre)
  • [2024-06-02] jpeg-xl 0.8.2-4 MIGRATED to testing (Debian testing watch)
  • [2024-05-31] Accepted jpeg-xl 0.8.2-4 (source) into unstable (Mathieu Malaterre)
  • [2024-05-22] Accepted jpeg-xl 0.8.2-3 (source) into experimental (Mathieu Malaterre)
  • [2024-05-21] Accepted jpeg-xl 0.8.2-2 (source) into experimental (Mathieu Malaterre)
  • 1
  • 2
bugs [bug history graph]
  • all: 3
  • RC: 0
  • I&N: 3
  • M&W: 0
  • F&P: 0
  • patch: 0
links
  • homepage
  • lintian (2, 1)
  • buildd: logs, checks, reproducibility, cross
  • popcon
  • browse source code
  • edit tags
  • other distros
  • security tracker
  • debian patches
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 0.11.1-4

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing