[Git][security-tracker-team/security-tracker][master] Add new libheif issues
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Wed Sep 23 14:42:38 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
c9726d9a by Salvatore Bonaccorso at 2026-09-23T15:40:10+02:00
Add new libheif issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,3 +1,21 @@
+CVE-2026-XXXX [GHSA-v8qw-hwjv-44hw: AV1/libaom path allows allocation before libheif rejects mismatched coded dimensions]
+ - libheif <unfixed>
+ NOTE: https://github.com/strukturag/libheif/security/advisories/GHSA-v8qw-hwjv-44hw
+CVE-2026-XXXX [GHSA-qfj5-c4pq-q998: Out-of-bounds heap read in unc_encoder_rgb_pixel_interleave when an alpha plane is attached to an image whose chroma format carries no alpha]
+ - libheif <unfixed>
+ NOTE: https://github.com/strukturag/libheif/security/advisories/GHSA-qfj5-c4pq-q998
+CVE-2026-XXXX [GHSA-qwpf-5wf7-r996: Heap-use-after-free and double free in ImageItem::encode_to_bitstream_and_boxes (shallow copy of ImageDescription::m_tai_timestamp)]
+ - libheif <unfixed>
+ NOTE: https://github.com/strukturag/libheif/security/advisories/GHSA-qwpf-5wf7-r996
+CVE-2026-XXXX [GHSA-9c75-9g8r-4728: JPEG 2000 pclr zero-column allocation amplification bypasses max_total_memory]
+ - libheif <unfixed>
+ NOTE: https://github.com/strukturag/libheif/security/advisories/GHSA-9c75-9g8r-4728
+CVE-2026-XXXX [GHSA-r7gr-2xm2-23wf: Heap out-of-bounds read in libheif alpha compositing via mismatched per-channel bit depths (uncompressed codec)]
+ - libheif <unfixed>
+ NOTE: https://github.com/strukturag/libheif/security/advisories/GHSA-r7gr-2xm2-23wf
+CVE-2026-XXXX [GHSA-7pwf-qh74-p35w: Caller-configured security limits not enforced for MINI-box parsing]
+ - libheif <unfixed>
+ NOTE: https://github.com/strukturag/libheif/security/advisories/GHSA-7pwf-qh74-p35w
CVE-2026-XXXX [GHSA-xq87-9rrm-6wqw]
- freerdp3 3.32.0+dfsg-1
- freerdp2 <removed>
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c9726d9aa64c5637351f3150900479e64657f974
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c9726d9aa64c5637351f3150900479e64657f974
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260923/79e719cd/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list