Kestrel
대시보드로 돌아가기
CVE-2026-52834HIGH· 7.3GHSA대응게시일: 2026. 07. 02.수정일: 2026. 07. 02.

jxl-grid on 32-bit platforms has an out-of-bounds writes due to integer overflow

위협 신호 · CVSS · EPSS · KEV

정기 패치· 높은 악용 신호 없음
CVSS
7.3high

이론적 심각도 점수

EPSS

예측 데이터 없음

KEV
미등재

실측 악용 기록 없음

권장 대응 기한차기 업그레이드 시CISA SSVC 기준

별도 긴급 패치 불필요 — 정기 시스템 업그레이드 주기에 맞춰 조치

· KEV 미등재 · 자동화 어려움 · 부분 영향 · 내부 한정

CVSS 벡터 · 메트릭

악용 경로
공격 벡터로컬
공격 복잡도높음
필요 권한불필요
사용자 상호작용불필요
범위변경
영향
기밀성 영향낮음
무결성 영향낮음
가용성 영향높음
버전별 점수
CVSS 3.17.3HIGH
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:H

상세 설명

Summary

On 32-bit platforms, decoding a crafted image may lead to out-of-bounds writes due to integer overflow in length calculation.

Details & PoC

The test listed below fail under miri with command cargo +nightly miri test --release -p jxl-grid

Or you can use Address Sanitizer, which ignores Rust-specific UB like aliasing but still flags out-of-bounds accesses:

RUSTFLAGS=-Zsanitizer=address cargo +nightly test -Zbuild-std -p jxl-grid --release --target x86_64-unknown-linux-gnu

The following tests should be appended to crates/jxl-grid/src/test/subgrids.rs:

text
1mod miri_ub {
2 use super::*;
3
4 // `AlignedGrid::with_alloc_tracker` computes `width * height` unchecked. In release, overflow
5 // can create a tiny backing buffer for huge logical dimensions.
6 #[test]
7 fn aligned_grid_dimension_product_overflows() {
8 let width = usize::MAX / 2 + 1;
9 let mut grid = AlignedGrid::<u8>::with_alloc_tracker(width, 2, None).unwrap();
10 let mut subgrid = grid.as_subgrid_mut();
11 *subgrid.get_mut(0, 1) = 1;
12 std::hint::black_box(grid);
13 }
14}

This issue can be reachable through decoding a crafted image in two ways:

  1. Huge actual frame
    A frame such as 65536 x 65536 passes the current frame area limit (2^32 <= 2^40) but overflows usize element count on 32-bit. Rendering then allocates too-small AlignedGrids in modular/VarDCT/filter paths and later writes through mutable subgrids.

  2. Huge canvas plus tiny cropped frame
    This is the more practical “small payload, huge logical output” case. A bitstream-controlled frame crop can be tiny, but if the canvas/default requested region is huge, composition can allocate an output grid sized to the canvas/ROI at crates/jxl-render/src/blend.rs. That is bitstream frame cropping, not API crop. With a 32-bit target and a full requested image region whose area overflows, this can happen through ordinary render_frame().

Impact

On 32-bit platforms this can cause out-of-bounds writes with attacker-controlled data when decoding a crafted JPEG XL image. This could allow arbitrary code execution.

AI 심층 분석

공격 시나리오 · 재현 가능한 PoC 페이로드 · 즉시 적용 가능한 차단 패치를 한 번에 받아 보세요. 보안 운영팀이 그대로 점검·티켓팅에 쓸 수 있는 형태로 정리해 드립니다.