Bug 2384428 - libjxl on EPEL on v0.7.0 (and v0.10.3) while newer versions v0.7.2 (and v0.10.4) have been out since 2024 november
Summary: libjxl on EPEL on v0.7.0 (and v0.10.3) while newer versions v0.7.2 (and v0.10...
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Fedora EPEL
Classification: Fedora
Component: jpegxl
Version: epel8
Hardware: x86_64
OS: Linux
unspecified
medium
Target Milestone: ---
Assignee: Dominik 'Rathann' Mierzejewski
QA Contact:
URL: https://pkgs.org/search/?q=libjxl
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2025-07-30 07:24 UTC by wesley.devree
Modified: 2025-08-21 00:52 UTC (History)
5 users (show)

Fixed In Version: jpegxl-0.10.4-1.el10_1 jpegxl-0.10.4-1.el10_0
Clone Of:
Environment:
Last Closed: 2025-08-21 00:36:27 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description wesley.devree 2025-07-30 07:24:57 UTC
We noticed recently that a few systems running on RHEL 8 / 9 use libjxl on version v0.7.0 but v0.7.2 adresses two CVE's which are rated 6.9 but allow out of bounds read's and write's.

Through this bug report i would like to request the versions atleast for EPEL 8 and 9 to be upgraded to v0.7.2 so everyone can safely and easily update this dependency. If possible upgrading the package from v0.10.3 for EPEL 10 to v0.10.4 to address the same vunerability would be great aswell if those running on the newest RHEL 10 OS.

Reproducible: Always

Steps to Reproduce:
1. Configure local system to use EPEL repositories
2. Install libjxl with dnf
3. Verify the currently installed version with that on the releases page of libjxl: https://github.com/libjxl/libjxl/releases
Actual Results:
v0.7.0 is installed not v0.7.2

Expected Results:
v0.7.2 is installed

Comment 1 Fedora Update System 2025-08-12 16:00:39 UTC
FEDORA-EPEL-2025-6117766f4b (jpegxl-0.7.2-1.el8) has been submitted as an update to Fedora EPEL 8.
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2025-6117766f4b

Comment 2 Fedora Update System 2025-08-12 22:16:44 UTC
FEDORA-EPEL-2025-f70deeaa88 (jpegxl-0.7.2-2.el9) has been submitted as an update to Fedora EPEL 9.
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2025-f70deeaa88

Comment 3 Fedora Update System 2025-08-12 23:09:34 UTC
FEDORA-EPEL-2025-496f3e6aeb (jpegxl-0.10.4-1.el10_0) has been submitted as an update to Fedora EPEL 10.0.
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2025-496f3e6aeb

Comment 4 Fedora Update System 2025-08-13 01:26:32 UTC
FEDORA-EPEL-2025-f70deeaa88 has been pushed to the Fedora EPEL 9 testing repository.

You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2025-f70deeaa88

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 5 Fedora Update System 2025-08-13 01:35:32 UTC
FEDORA-EPEL-2025-5304230dce has been pushed to the Fedora EPEL 10.1 testing repository.

You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2025-5304230dce

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 6 Fedora Update System 2025-08-13 01:40:14 UTC
FEDORA-EPEL-2025-496f3e6aeb has been pushed to the Fedora EPEL 10.0 testing repository.

You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2025-496f3e6aeb

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 7 Fedora Update System 2025-08-13 01:44:16 UTC
FEDORA-EPEL-2025-6117766f4b has been pushed to the Fedora EPEL 8 testing repository.

You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2025-6117766f4b

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 8 Fedora Update System 2025-08-21 00:25:48 UTC
FEDORA-EPEL-2025-f70deeaa88 (jpegxl-0.7.2-2.el9) has been pushed to the Fedora EPEL 9 stable repository.
If problem still persists, please make note of it in this bug report.

Comment 9 Fedora Update System 2025-08-21 00:36:27 UTC
FEDORA-EPEL-2025-5304230dce (jpegxl-0.10.4-1.el10_1) has been pushed to the Fedora EPEL 10.1 stable repository.
If problem still persists, please make note of it in this bug report.

Comment 10 Fedora Update System 2025-08-21 00:44:10 UTC
FEDORA-EPEL-2025-496f3e6aeb (jpegxl-0.10.4-1.el10_0) has been pushed to the Fedora EPEL 10.0 stable repository.
If problem still persists, please make note of it in this bug report.

Comment 11 Fedora Update System 2025-08-21 00:52:53 UTC
FEDORA-EPEL-2025-6117766f4b (jpegxl-0.7.2-1.el8) has been pushed to the Fedora EPEL 8 stable repository.
If problem still persists, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.