This can be done by causing the decoder to reference an outside-image-bound area in a subsequent patches. An incorrect optimization causes the decoder to omit populating those areas.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 12 Feb 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-125 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Wed, 11 Feb 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Google
Google libjxl |
|
| Vendors & Products |
Google
Google libjxl |
|
| Metrics |
ssvc
|
Wed, 11 Feb 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A specially-crafted file can cause libjxl's decoder to read pixel data from uninitialized (but allocated) memory. This can be done by causing the decoder to reference an outside-image-bound area in a subsequent patches. An incorrect optimization causes the decoder to omit populating those areas. | |
| Title | libjxl: Uninitialized memory read in decoder due to incorrect optimization in patch handling | |
| Weaknesses | CWE-908 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Google
Published:
Updated: 2026-02-11T21:41:40.223Z
Reserved: 2025-10-29T16:11:30.108Z
Link: CVE-2025-12474
Updated: 2026-02-11T21:41:33.922Z
Status : Awaiting Analysis
Published: 2026-02-11T16:15:53.647
Modified: 2026-02-11T18:06:04.010
Link: CVE-2025-12474
OpenCVE Enrichment
Updated: 2026-02-11T21:37:50Z