[Git][security-tracker-team/security-tracker][master] Add new libheif issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Sep 23 14:42:38 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
c9726d9a by Salvatore Bonaccorso at 2026-09-23T15:40:10+02:00
Add new libheif issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,21 @@
+CVE-2026-XXXX [GHSA-v8qw-hwjv-44hw: AV1/libaom path allows allocation before libheif rejects mismatched coded dimensions]
+	- libheif <unfixed>
+	NOTE: https://github.com/strukturag/libheif/security/advisories/GHSA-v8qw-hwjv-44hw
+CVE-2026-XXXX [GHSA-qfj5-c4pq-q998: Out-of-bounds heap read in unc_encoder_rgb_pixel_interleave when an alpha plane is attached to an image whose chroma format carries no alpha]
+	- libheif <unfixed>
+	NOTE: https://github.com/strukturag/libheif/security/advisories/GHSA-qfj5-c4pq-q998
+CVE-2026-XXXX [GHSA-qwpf-5wf7-r996: Heap-use-after-free and double free in ImageItem::encode_to_bitstream_and_boxes (shallow copy of ImageDescription::m_tai_timestamp)]
+	- libheif <unfixed>
+	NOTE: https://github.com/strukturag/libheif/security/advisories/GHSA-qwpf-5wf7-r996
+CVE-2026-XXXX [GHSA-9c75-9g8r-4728: JPEG 2000 pclr zero-column allocation amplification bypasses max_total_memory]
+	- libheif <unfixed>
+	NOTE: https://github.com/strukturag/libheif/security/advisories/GHSA-9c75-9g8r-4728
+CVE-2026-XXXX [GHSA-r7gr-2xm2-23wf: Heap out-of-bounds read in libheif alpha compositing via mismatched per-channel bit depths (uncompressed codec)]
+	- libheif <unfixed>
+	NOTE: https://github.com/strukturag/libheif/security/advisories/GHSA-r7gr-2xm2-23wf
+CVE-2026-XXXX [GHSA-7pwf-qh74-p35w: Caller-configured security limits not enforced for MINI-box parsing]
+	- libheif <unfixed>
+	NOTE: https://github.com/strukturag/libheif/security/advisories/GHSA-7pwf-qh74-p35w
 CVE-2026-XXXX [GHSA-xq87-9rrm-6wqw]
 	- freerdp3 3.32.0+dfsg-1
 	- freerdp2 <removed>



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c9726d9aa64c5637351f3150900479e64657f974

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c9726d9aa64c5637351f3150900479e64657f974
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260923/79e719cd/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list