[Git][security-tracker-team/security-tracker][master] Update information on CVE-2026-84383 and CVE-2026-62377
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Fri Sep 4 04:56:47 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
d87dc51c by Salvatore Bonaccorso at 2026-09-04T05:56:17+02:00
Update information on CVE-2026-84383 and CVE-2026-62377
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -2992,6 +2992,7 @@ CVE-2026-84383 [GHSA-g89c-p67h-r497: Heap buffer overflow in `scale_nearest_neig
[trixie] - libheif <not-affected> (Vulnerable code not present, introduced in 1.22)
[bookworm] - libheif <not-affected> (Vulnerable code not present, introduced in 1.22)
NOTE: https://github.com/strukturag/libheif/security/advisories/GHSA-g89c-p67h-r497
+ NOTE: Introduced after: https://github.com/strukturag/libheif/commit/de9d2b951761ffcca2c835d190c52903c2a6bc26 (v1.22.0)
NOTE: Fixed by: https://github.com/strukturag/libheif/commit/f4fb8bde4704ebb46e46ff9fb94407c9774153b2 (v1.23.2)
CVE-2026-83497 (Unrestricted deserialization of untrusted data in the cursor paginatio ...)
NOT-FOR-US: Amazon
@@ -16956,6 +16957,7 @@ CVE-2026-62377 (libheif is a HEIF and AVIF file format decoder and encoder. In 1
[bookworm] - libheif <not-affected> (Vulnerable code not present, introduced in 1.20)
NOTE: https://github.com/strukturag/libheif/security/advisories/GHSA-9ww4-9v47-m7pj
NOTE: https://github.com/strukturag/libheif/issues/1844
+ NOTE: Introduced after: https://github.com/strukturag/libheif/commit/fb27472da6692bf7b0efd819eb22c52819aae90c (v1.20.0)
NOTE: Fixed by: https://github.com/strukturag/libheif/commit/e1a0bc1c1ae74f8075eaca30a1cdb2b9bee698d3 (v1.23.1)
CVE-2026-62291 (libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.0 ...)
- libheif 1.23.1-1
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d87dc51cd3aa424ed9ea3b4f8d4033bcbf4d6c9d
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d87dc51cd3aa424ed9ea3b4f8d4033bcbf4d6c9d
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260904/a15c8fdd/attachment.htm>
More information about the debian-security-tracker-commits
mailing list