[Git][security-tracker-team/security-tracker][master] 2 commits: Triage libheif CVEs
Aron Xu (@aron)
aron at debian.org
Thu Aug 6 12:41:49 BST 2026
Aron Xu pushed to branch master at Debian Security Tracker / security-tracker
Commits:
83c9a465 by Aron Xu at 2026-08-06T19:40:35+08:00
Triage libheif CVEs
- - - - -
ac0638cc by Aron Xu at 2026-08-06T19:41:17+08:00
Take libheif
- - - - -
2 changed files:
- data/CVE/list
- data/dsa-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -60670,10 +60670,12 @@ CVE-2026-41074 (RT is an open source, enterprise-grade issue and ticket tracking
NOTE: https://github.com/bestpractical/rt/security/advisories/GHSA-265j-qx4w-256j
CVE-2026-41071 (libheif is a HEIF and AVIF file format decoder and encoder. In version ...)
- libheif 1.23.1-1 (bug #1137524)
+ [trixie] - libheif <not-affected> (Vulnerable code introduced in 1.20.0)
NOTE: https://github.com/strukturag/libheif/security/advisories/GHSA-xj92-xjff-h8w3
NOTE: Fixed by: https://github.com/strukturag/libheif/commit/f20c81745e917b4c496615140385c86d7a2fa58d (v1.22.0)
CVE-2026-41069 (libheif is a HEIF and AVIF file format decoder and encoder. In version ...)
- libheif 1.23.1-1 (bug #1137524)
+ [trixie] - libheif <not-affected> (Vulnerable code introduced in 1.20.0)
NOTE: https://github.com/strukturag/libheif/security/advisories/GHSA-p82x-fpmv-576r
CVE-2026-40864 (JupyterHub is software that allows users to create a multi-user server ...)
- jupyterhub <unfixed> (bug #1143060)
@@ -62546,6 +62548,7 @@ CVE-2026-33633 (Kitty is a cross-platform GPU based terminal. Versions 0.46.2 an
NOTE: Fixed by: https://github.com/kovidgoyal/kitty/commit/48ab623f594d60dbbfb1e767d9686d380ce547fb (v0.47.0)
CVE-2026-50142
- libheif 1.23.1-1
+ [trixie] - libheif <not-affected> (Vulnerable code introduced in 1.20.0)
NOTE: https://github.com/strukturag/libheif/security/advisories/GHSA-jvmp-j3cw-84mh
CVE-2026-48029 (libheif is a HEIF and AVIF file format decoder and encoder. Versions 1 ...)
- libheif 1.23.1-1
@@ -62558,9 +62561,13 @@ CVE-2026-47247 (libheif is a HEIF and AVIF file format decoder and encoder. Prio
NOTE: https://github.com/strukturag/libheif/security/advisories/GHSA-2vh6-whr3-cmq3
CVE-2026-47251 (libheif is a HEIF and AVIF file format decoder and encoder. The fix fo ...)
- libheif 1.23.1-1
+ [trixie] - libheif <not-affected> (Vulnerable code introduced in 1.22.0)
+ NOTE: Flaw in the bounds check added by the fix for CVE-2026-3949 (b97c8b5f, v1.22.0)
+ NOTE: The 'vvdec' backend is not built for the Debian binary packages
NOTE: https://github.com/strukturag/libheif/security/advisories/GHSA-p6q9-fhf2-vj9v
CVE-2026-47254 (libheif is a HEIF and AVIF file format decoder and encoder. Prior to v ...)
- libheif 1.23.1-1
+ [trixie] - libheif <not-affected> (Vulnerable code introduced in 1.20.0)
NOTE: https://github.com/strukturag/libheif/security/advisories/GHSA-wqjg-4x9g-6cvg
CVE-2026-47714 (libheif is a HEIF and AVIF file format decoder and encoder. In version ...)
- libheif 1.23.1-1
@@ -62570,6 +62577,9 @@ CVE-2026-32882 (libheif is a HEIF and AVIF file format decoder and encoder. Vers
NOTE: https://github.com/strukturag/libheif/security/advisories/GHSA-hg7q-rjr2-8x46
CVE-2026-32814 (libheif is a HEIF and AVIF file format decoder and encoder. In version ...)
- libheif 1.23.1-1 (bug #1137524)
+ [trixie] - libheif <not-affected> (Vulnerable code introduced in 1.21.0)
+ NOTE: Needs the strict_decoding leniency in ImageItem_Grid::decode_and_paste_tile_image()
+ NOTE: added by 0f17e1cd (v1.21.0); in 1.19.8 a tile decode error aborts the grid decode
NOTE: https://github.com/strukturag/libheif/security/advisories/GHSA-4m8r-34pg-rvwc
NOTE: https://github.com/strukturag/libheif/commit/724ad42638c025993a0de8b53b180e465397c500 (v1.22.0)
CVE-2026-32741 (libheif is a HEIF and AVIF file format decoder and encoder. Versions 1 ...)
@@ -62582,10 +62592,12 @@ CVE-2026-32740 (libheif is a HEIF and AVIF file format decoder and encoder. Vers
NOTE: https://github.com/strukturag/libheif/commit/6721f307ad684804b735e917dde7d372c5faae31 (v1.22.0)
CVE-2026-32739 (libheif is a HEIF and AVIF file format decoder and encoder. In version ...)
- libheif 1.23.1-1 (bug #1137524)
+ [trixie] - libheif <not-affected> (Vulnerable code introduced in 1.20.0)
NOTE: https://github.com/strukturag/libheif/security/advisories/GHSA-j9g7-q9hv-gq8c
NOTE: https://github.com/strukturag/libheif/commit/723b58d6ca329b2743822951aeaf3299c7410448 (v1.22.0)
CVE-2026-32738 (libheif is a HEIF and AVIF file format decoder and encoder. In version ...)
- libheif 1.23.1-1 (bug #1137524)
+ [trixie] - libheif <not-affected> (Vulnerable code introduced in 1.20.0)
NOTE: https://github.com/strukturag/libheif/security/advisories/GHSA-7f2h-cmpf-v9ww
NOTE: https://github.com/strukturag/libheif/commit/bdaa37728442800497ea224bd232ca25e2f9bdff (v1.22.0)
CVE-2026-32134 (NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. ...)
=====================================
data/dsa-needed.txt
=====================================
@@ -62,7 +62,7 @@ kamailio
kitty
Maintainer proposed debdiff for review in https://bugs.debian.org/1139898#15
--
-libheif
+libheif (aron)
possibly best to move to 1.23.0
--
librabbitmq
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/f651ceeea5148cb0ea7180ce9156c6a11a2c4a84...ac0638cc71efb73983a03bc596d622a4245574f9
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/f651ceeea5148cb0ea7180ce9156c6a11a2c4a84...ac0638cc71efb73983a03bc596d622a4245574f9
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260806/3e7bfc16/attachment.htm>
More information about the debian-security-tracker-commits
mailing list