[Git][security-tracker-team/security-tracker][master] Update information on CVE-2026-84383 and CVE-2026-62377

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Sep 4 04:56:47 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
d87dc51c by Salvatore Bonaccorso at 2026-09-04T05:56:17+02:00
Update information on CVE-2026-84383 and CVE-2026-62377

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -2992,6 +2992,7 @@ CVE-2026-84383 [GHSA-g89c-p67h-r497: Heap buffer overflow in `scale_nearest_neig
 	[trixie] - libheif <not-affected> (Vulnerable code not present, introduced in 1.22)
 	[bookworm] - libheif <not-affected> (Vulnerable code not present, introduced in 1.22)
 	NOTE: https://github.com/strukturag/libheif/security/advisories/GHSA-g89c-p67h-r497
+	NOTE: Introduced after: https://github.com/strukturag/libheif/commit/de9d2b951761ffcca2c835d190c52903c2a6bc26 (v1.22.0)
 	NOTE: Fixed by: https://github.com/strukturag/libheif/commit/f4fb8bde4704ebb46e46ff9fb94407c9774153b2 (v1.23.2)
 CVE-2026-83497 (Unrestricted deserialization of untrusted data in the cursor paginatio ...)
 	NOT-FOR-US: Amazon
@@ -16956,6 +16957,7 @@ CVE-2026-62377 (libheif is a HEIF and AVIF file format decoder and encoder. In 1
 	[bookworm] - libheif <not-affected> (Vulnerable code not present, introduced in 1.20)
 	NOTE: https://github.com/strukturag/libheif/security/advisories/GHSA-9ww4-9v47-m7pj
 	NOTE: https://github.com/strukturag/libheif/issues/1844
+	NOTE: Introduced after: https://github.com/strukturag/libheif/commit/fb27472da6692bf7b0efd819eb22c52819aae90c (v1.20.0)
 	NOTE: Fixed by: https://github.com/strukturag/libheif/commit/e1a0bc1c1ae74f8075eaca30a1cdb2b9bee698d3 (v1.23.1)
 CVE-2026-62291 (libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.0  ...)
 	- libheif 1.23.1-1



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d87dc51cd3aa424ed9ea3b4f8d4033bcbf4d6c9d

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d87dc51cd3aa424ed9ea3b4f8d4033bcbf4d6c9d
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260904/a15c8fdd/attachment.htm>


More information about the debian-security-tracker-commits mailing list