[Git][security-tracker-team/security-tracker][master] 2 commits: Track status for libheif CVEs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Fri Sep 4 04:53:25 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
14352c20 by Matheus Polkorny at 2026-09-03T18:51:20-03:00
Track status for libheif CVEs
- - - - -
d4edbe4d by Salvatore Bonaccorso at 2026-09-04T05:53:17+02:00
Merge branch 'master' into 'master'
Track status for libheif CVEs
See merge request security-tracker-team/security-tracker!326
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -2989,6 +2989,8 @@ CVE-2025-63607 (TechStore 1.0 is vulnerable to Cross Site Scripting (XSS). In co
TODO: check
CVE-2026-84383 [GHSA-g89c-p67h-r497: Heap buffer overflow in `scale_nearest_neighbor()` via duplicate Alpha planes from nested `iden`/`auxl` items]
- libheif 1.23.2-1
+ [trixie] - libheif <not-affected> (Vulnerable code not present, introduced in 1.22)
+ [bookworm] - libheif <not-affected> (Vulnerable code not present, introduced in 1.22)
NOTE: https://github.com/strukturag/libheif/security/advisories/GHSA-g89c-p67h-r497
NOTE: Fixed by: https://github.com/strukturag/libheif/commit/f4fb8bde4704ebb46e46ff9fb94407c9774153b2 (v1.23.2)
CVE-2026-83497 (Unrestricted deserialization of untrusted data in the cursor paginatio ...)
@@ -16950,7 +16952,8 @@ CVE-2026-62441 (Vulnerability in the Oracle Hyperion Calculation Manager product
NOT-FOR-US: Oracle
CVE-2026-62377 (libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.0 ...)
- libheif 1.23.1-1
- [trixie] - libheif <no-dsa> (Minor issue)
+ [trixie] - libheif <not-affected> (Vulnerable code not present, introduced in 1.20)
+ [bookworm] - libheif <not-affected> (Vulnerable code not present, introduced in 1.20)
NOTE: https://github.com/strukturag/libheif/security/advisories/GHSA-9ww4-9v47-m7pj
NOTE: https://github.com/strukturag/libheif/issues/1844
NOTE: Fixed by: https://github.com/strukturag/libheif/commit/e1a0bc1c1ae74f8075eaca30a1cdb2b9bee698d3 (v1.23.1)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/ad80c4b8a45f48c20bb2f585ed6c8fa3d16ca884...d4edbe4d71962d5bc8117cc33bbb74b0b994598c
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/ad80c4b8a45f48c20bb2f585ed6c8fa3d16ca884...d4edbe4d71962d5bc8117cc33bbb74b0b994598c
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260904/e82c38ec/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list