Your message dated Sat, 22 Aug 2026 19:49:47 +0000
with message-id <[email protected]>
and subject line Bug#1138575: fixed in jpeg-xl 0.11.2-5.1
has caused the Debian Bug report #1138575,
regarding jpeg-xl: CVE-2025-70103
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1138575: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1138575
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: jpeg-xl
Version: 0.11.2-5
Severity: important
Tags: security upstream
Forwarded: https://github.com/libjxl/libjxl/issues/4337
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi,
The following vulnerability was published for jpeg-xl.
CVE-2025-70103[0]:
| Heap buffer overflow vulnerability in libjxl 0.12.0 via crafted PBM
| images to the jxl::extras::DecodeImagePNM function in file
| lib/extras/dec/pnm.cc.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2025-70103
https://www.cve.org/CVERecord?id=CVE-2025-70103
[1] https://github.com/libjxl/libjxl/issues/4337
[2] https://www.openwall.com/lists/oss-security/2026/05/30/7
[3] https://github.com/libjxl/libjxl/pull/4380
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore
--- End Message ---
--- Begin Message ---
Source: jpeg-xl
Source-Version: 0.11.2-5.1
Done: Adrian Bunk <[email protected]>
We believe that the bug you reported is fixed in the latest version of
jpeg-xl, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Adrian Bunk <[email protected]> (supplier of updated jpeg-xl package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Thu, 13 Aug 2026 16:09:49 +0300
Source: jpeg-xl
Architecture: source
Version: 0.11.2-5.1
Distribution: unstable
Urgency: medium
Maintainer: Debian PhotoTools Maintainers
<[email protected]>
Changed-By: Adrian Bunk <[email protected]>
Closes: 1138575 1142476
Changes:
jpeg-xl (0.11.2-5.1) unstable; urgency=medium
.
* Non-maintainer upload.
* CVE-2025-70103: Buffer overflow in PNM decoder
(Closes: #1138575)
* CVE-2026-52584: Buffer overflow in APNG decoder
(Closes: #1142476)
* Backport upstream fix for FTBFS on x32.
Checksums-Sha1:
0287faf48e51f8478358b55f375240abbe2b7a23 3215 jpeg-xl_0.11.2-5.1.dsc
57ef93c50262422f1e9d2d79be1ed624bed5b79b 20680 jpeg-xl_0.11.2-5.1.debian.tar.xz
Checksums-Sha256:
547a1c75f467336b82c7178bb2390a3df5d68eddffa77ca7679754a5c3956f89 3215
jpeg-xl_0.11.2-5.1.dsc
45b2b711b09fc3d6362cb2604befcbcbd8f0ba5937e65ad88163a1c8c66bc0dd 20680
jpeg-xl_0.11.2-5.1.debian.tar.xz
Files:
4b2da2e56f9179e2e4f2ebb031333c50 3215 graphics optional jpeg-xl_0.11.2-5.1.dsc
2bad471218d2c1fce5d4a07d1e9d2a1a 20680 graphics optional
jpeg-xl_0.11.2-5.1.debian.tar.xz
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEOvp1f6xuoR0v9F3wiNJCh6LYmLEFAmp9zNQACgkQiNJCh6LY
mLH8rQ/+KGA+X+q8fwWqwiENJ1fI0JJMflfLZhy24mwvjD0NQ6Bg5bPcClO8xN+4
GePwVutuSSLjntTcPmFX2x0GPw81vYiXnjDJy8M1HcWlaxuNGLCdGprcsZfQwJ3G
V8w/am9zwPNaayc5D7NnJ55RO0C0wgsvKL2VwJFHDgswQpB2nSPMwNm4s4RYQLah
SVhprreCfOrnEsMR6tselC784WlG6LtykdvoU2gqGVz98h82zE4h7/MqMTJsqcew
gNiZcbWij0FGIcYsCeV/tJlrs42wtx71D2zvGZPumBrQL15Zp3jeG1CTOb+9ofMi
Tz4b8hFHcH5q3vJ8bXroiezgKx8Je8oQQ8VKlEjCDbKUJouquqgO3plNA/Drx+5B
fNWyPU6l/Jq2RRExxUhGMq7EZHA7jvOp1Mq8Lz5DENP1i5rXupQta/MCc7VwmlgJ
iE5neKfj3DA+58IMtZ4jnciG2bqM+eB6IvYNp1VOcs8JdrWvhVJtoOHf8dDTVJwZ
UEhh9tkbQZxcHDpWGD8+IujIWxU/JAX20Ns5/z2FeGeX9xay4pjgSz0WFinv0YnE
Mkyo4/kLfoBzfI0ehBl3BfG7r4ImQC1nG7xyLVucxM2vSRkyLie/SYfyCs+nTnah
LxtiH/Cz20tMGtglV4CsVdMsCE2qukbgY+Q+EITnuGXGiucT08E=
=w1Yt
-----END PGP SIGNATURE-----
pgpv7fQEZKovg.pgp
Description: PGP signature
--- End Message ---