[Git][security-tracker-team/security-tracker][master] remaining libheif issues from 1.23.3
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Thu Sep 3 19:35:52 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
42ea7d80 by Moritz Muehlenhoff at 2026-09-03T20:35:09+02:00
remaining libheif issues from 1.23.3
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -151,6 +151,20 @@ CVE-2026-XXXX [decoder deadlock (DoS) via alpha-aux reference cycle]
CVE-2026-84451 [Incomplete fix for GHSA-73p7-m7gg-w2jv leaves libheif 1.23.1 vulnerable to an out-of-bounds read]
- libheif 1.23.3-1
NOTE: https://github.com/strukturag/libheif/security/advisories/GHSA-hh47-fhqr-cj2r
+CVE-2026-XXXX [heap OOB read / info disclosure (Op_YCbCr420_to_RRGGBBaa]
+ - libheif 1.23.3-1
+ NOTE: https://github.com/strukturag/libheif/security/advisories/GHSA-w7mc-p8jc-p853
+CVE-2026-XXXX [Heap buffer overflow in SVT-AV1 encoder for high-bit-depth alpha channels]
+ - libheif 1.23.3-1
+ NOTE: https://github.com/strukturag/libheif/security/advisories/GHSA-4jqm-2x34-6f6r
+CVE-2026-XXXX [Heap-buffer-overflow read in uncompressed (`uncv`) HEIF sequence RGB conversion for odd-height 4:2:0 frames]
+ - libheif 1.23.3-1
+ [trixie] - libheif <not-affected> (Introduced in 1.20)
+ [bookworm] - libheif <not-affected> (Introduced in 1.20)
+ NOTE: https://github.com/strukturag/libheif/security/advisories/GHSA-4h82-g446-83fm
+CVE-2026-XXXX [Out-of-bounds read in RGB-YCbCr identity-matrix colour conversion with mismatched per-channel bit depths]
+ - libheif 1.23.3-1
+ NOTE: https://github.com/strukturag/libheif/security/advisories/GHSA-9rj8-5mp5-26c9
CVE-2026-65107 [Fix sbcast shared objects skipping credential verification, Fix possible slurmd crash on invalid sbcast filenames]
- slurm-wlm <unfixed> (bug #1146563)
NOTE: https://github.com/SchedMD/slurm/blob/slurm-26.05/CHANGELOG/slurm-26.05.md#changes-in-26054
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/42ea7d80cb38ed4e960a83b6bce07c08176c0224
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/42ea7d80cb38ed4e960a83b6bce07c08176c0224
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260903/2bbcd2c5/attachment.htm>
More information about the debian-security-tracker-commits
mailing list