[Git][security-tracker-team/security-tracker][master] 2 commits: Triage libheif CVEs

Aron Xu (@aron) aron at debian.org
Thu Aug 6 12:41:49 BST 2026



Aron Xu pushed to branch master at Debian Security Tracker / security-tracker


Commits:
83c9a465 by Aron Xu at 2026-08-06T19:40:35+08:00
Triage libheif CVEs

- - - - -
ac0638cc by Aron Xu at 2026-08-06T19:41:17+08:00
Take libheif

- - - - -


2 changed files:

- data/CVE/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -60670,10 +60670,12 @@ CVE-2026-41074 (RT is an open source, enterprise-grade issue and ticket tracking
 	NOTE: https://github.com/bestpractical/rt/security/advisories/GHSA-265j-qx4w-256j
 CVE-2026-41071 (libheif is a HEIF and AVIF file format decoder and encoder. In version ...)
 	- libheif 1.23.1-1 (bug #1137524)
+	[trixie] - libheif <not-affected> (Vulnerable code introduced in 1.20.0)
 	NOTE: https://github.com/strukturag/libheif/security/advisories/GHSA-xj92-xjff-h8w3
 	NOTE: Fixed by: https://github.com/strukturag/libheif/commit/f20c81745e917b4c496615140385c86d7a2fa58d (v1.22.0)
 CVE-2026-41069 (libheif is a HEIF and AVIF file format decoder and encoder. In version ...)
 	- libheif 1.23.1-1 (bug #1137524)
+	[trixie] - libheif <not-affected> (Vulnerable code introduced in 1.20.0)
 	NOTE: https://github.com/strukturag/libheif/security/advisories/GHSA-p82x-fpmv-576r
 CVE-2026-40864 (JupyterHub is software that allows users to create a multi-user server ...)
 	- jupyterhub <unfixed> (bug #1143060)
@@ -62546,6 +62548,7 @@ CVE-2026-33633 (Kitty is a cross-platform GPU based terminal. Versions 0.46.2 an
 	NOTE: Fixed by: https://github.com/kovidgoyal/kitty/commit/48ab623f594d60dbbfb1e767d9686d380ce547fb (v0.47.0)
 CVE-2026-50142
 	- libheif 1.23.1-1
+	[trixie] - libheif <not-affected> (Vulnerable code introduced in 1.20.0)
 	NOTE: https://github.com/strukturag/libheif/security/advisories/GHSA-jvmp-j3cw-84mh
 CVE-2026-48029 (libheif is a HEIF and AVIF file format decoder and encoder. Versions 1 ...)
 	- libheif 1.23.1-1
@@ -62558,9 +62561,13 @@ CVE-2026-47247 (libheif is a HEIF and AVIF file format decoder and encoder. Prio
 	NOTE: https://github.com/strukturag/libheif/security/advisories/GHSA-2vh6-whr3-cmq3
 CVE-2026-47251 (libheif is a HEIF and AVIF file format decoder and encoder. The fix fo ...)
 	- libheif 1.23.1-1
+	[trixie] - libheif <not-affected> (Vulnerable code introduced in 1.22.0)
+	NOTE: Flaw in the bounds check added by the fix for CVE-2026-3949 (b97c8b5f, v1.22.0)
+	NOTE: The 'vvdec' backend is not built for the Debian binary packages
 	NOTE: https://github.com/strukturag/libheif/security/advisories/GHSA-p6q9-fhf2-vj9v
 CVE-2026-47254 (libheif is a HEIF and AVIF file format decoder and encoder. Prior to v ...)
 	- libheif 1.23.1-1
+	[trixie] - libheif <not-affected> (Vulnerable code introduced in 1.20.0)
 	NOTE: https://github.com/strukturag/libheif/security/advisories/GHSA-wqjg-4x9g-6cvg
 CVE-2026-47714 (libheif is a HEIF and AVIF file format decoder and encoder. In version ...)
 	- libheif 1.23.1-1
@@ -62570,6 +62577,9 @@ CVE-2026-32882 (libheif is a HEIF and AVIF file format decoder and encoder. Vers
 	NOTE: https://github.com/strukturag/libheif/security/advisories/GHSA-hg7q-rjr2-8x46
 CVE-2026-32814 (libheif is a HEIF and AVIF file format decoder and encoder. In version ...)
 	- libheif 1.23.1-1 (bug #1137524)
+	[trixie] - libheif <not-affected> (Vulnerable code introduced in 1.21.0)
+	NOTE: Needs the strict_decoding leniency in ImageItem_Grid::decode_and_paste_tile_image()
+	NOTE: added by 0f17e1cd (v1.21.0); in 1.19.8 a tile decode error aborts the grid decode
 	NOTE: https://github.com/strukturag/libheif/security/advisories/GHSA-4m8r-34pg-rvwc
 	NOTE: https://github.com/strukturag/libheif/commit/724ad42638c025993a0de8b53b180e465397c500 (v1.22.0)
 CVE-2026-32741 (libheif is a HEIF and AVIF file format decoder and encoder. Versions 1 ...)
@@ -62582,10 +62592,12 @@ CVE-2026-32740 (libheif is a HEIF and AVIF file format decoder and encoder. Vers
 	NOTE: https://github.com/strukturag/libheif/commit/6721f307ad684804b735e917dde7d372c5faae31 (v1.22.0)
 CVE-2026-32739 (libheif is a HEIF and AVIF file format decoder and encoder. In version ...)
 	- libheif 1.23.1-1 (bug #1137524)
+	[trixie] - libheif <not-affected> (Vulnerable code introduced in 1.20.0)
 	NOTE: https://github.com/strukturag/libheif/security/advisories/GHSA-j9g7-q9hv-gq8c
 	NOTE: https://github.com/strukturag/libheif/commit/723b58d6ca329b2743822951aeaf3299c7410448 (v1.22.0)
 CVE-2026-32738 (libheif is a HEIF and AVIF file format decoder and encoder. In version ...)
 	- libheif 1.23.1-1 (bug #1137524)
+	[trixie] - libheif <not-affected> (Vulnerable code introduced in 1.20.0)
 	NOTE: https://github.com/strukturag/libheif/security/advisories/GHSA-7f2h-cmpf-v9ww
 	NOTE: https://github.com/strukturag/libheif/commit/bdaa37728442800497ea224bd232ca25e2f9bdff (v1.22.0)
 CVE-2026-32134 (NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform.  ...)


=====================================
data/dsa-needed.txt
=====================================
@@ -62,7 +62,7 @@ kamailio
 kitty
   Maintainer proposed debdiff for review in https://bugs.debian.org/1139898#15
 --
-libheif
+libheif (aron)
   possibly best to move to 1.23.0
 --
 librabbitmq



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/f651ceeea5148cb0ea7180ce9156c6a11a2c4a84...ac0638cc71efb73983a03bc596d622a4245574f9

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/f651ceeea5148cb0ea7180ce9156c6a11a2c4a84...ac0638cc71efb73983a03bc596d622a4245574f9
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260806/3e7bfc16/attachment.htm>


More information about the debian-security-tracker-commits mailing list