[Git][security-tracker-team/security-tracker][master] DSA for libheif
Aron Xu (@aron)
aron at debian.org
Fri Aug 7 18:05:27 BST 2026
Aron Xu pushed to branch master at Debian Security Tracker / security-tracker
Commits:
254a3d5d by Aron Xu at 2026-08-08T01:05:14+08:00
DSA for libheif
Not moving to new version because of upstream regression:
https://github.com/strukturag/libheif/issues/1881
- - - - -
3 changed files:
- data/CVE/list
- data/DSA/list
- data/dsa-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -136144,7 +136144,6 @@ CVE-2025-68706 (A stack-based buffer overflow exists in the GoAhead-Webs HTTP da
NOT-FOR-US: KuWFi
CVE-2025-68431 (libheif is an HEIF and AVIF file format decoder and encoder. Prior to ...)
- libheif 1.21.2-1 (bug #1124317)
- [trixie] - libheif <no-dsa> (Minor issue)
[bookworm] - libheif <no-dsa> (Minor issue)
[bullseye] - libheif <postponed> (Minor issue, OOBR)
NOTE: https://github.com/strukturag/libheif/security/advisories/GHSA-j87x-4gmq-cqfq
=====================================
data/DSA/list
=====================================
@@ -1,3 +1,6 @@
+[08 Aug 2026] DSA-6417-1 libheif - security update
+ {CVE-2025-68431 CVE-2026-32740 CVE-2026-32741 CVE-2026-32882 CVE-2026-47178 CVE-2026-47247 CVE-2026-47709 CVE-2026-47714 CVE-2026-48029 CVE-2026-49271 CVE-2026-62289 CVE-2026-62292}
+ [trixie] - libheif 1.19.8-1+deb13u1
[07 Aug 2026] DSA-6416-1 jq - security update
{CVE-2024-53427 CVE-2026-32316 CVE-2026-40612 CVE-2026-41256 CVE-2026-41257 CVE-2026-43894 CVE-2026-43895 CVE-2026-43896 CVE-2026-44777 CVE-2026-47770 CVE-2026-49839 CVE-2026-54679}
[trixie] - jq 1.7.1-6+deb13u3
=====================================
data/dsa-needed.txt
=====================================
@@ -61,9 +61,6 @@ kamailio
kitty
Maintainer proposed debdiff for review in https://bugs.debian.org/1139898#15
--
-libheif (aron)
- possibly best to move to 1.23.0
---
librabbitmq
Florian Ernst is preparing updates
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/254a3d5df46ec6ac6bf807cff81ecd2d32e4efda
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/254a3d5df46ec6ac6bf807cff81ecd2d32e4efda
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260807/aff78a45/attachment.htm>
More information about the debian-security-tracker-commits
mailing list