VYPR

rpm package

opensuse/libheif&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/libheif&distro=openSUSE%20Tumbleweed

Vulnerabilities (35)

  • CVE-2026-84451MedSep 18, 2026
    affected < 1.23.4-1.1fixed 1.23.4-1.1

    libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.3, the no-icef full-item branch of unc_decoder::get_compressed_image_data_uncompressed() in libheif/codecs/uncompressed/unc_decoder.cc retains an addition-based range check that can wrap when a cra

  • CVE-2026-84450MedSep 18, 2026
    affected < 1.23.4-1.1fixed 1.23.4-1.1

    libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.3, a crafted image item containing a clap property and an ispe width or height greater than INT32_MAX + 1 can reach crop calculations through heif_image_handle_get_image_tiling(). Box_clap::left_ro

  • CVE-2026-84448MedSep 18, 2026
    affected < 1.23.4-1.1fixed 1.23.4-1.1

    libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1.23.2, the public heif_region_item_add_region_inline_mask_data() function in libheif/api/libheif/heif_regions.cc accepts mask_data_len without verifying that it equals the byte count required by width and heigh

  • CVE-2026-84447HigSep 18, 2026
    affected < 1.23.4-1.1fixed 1.23.4-1.1

    libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.1 and earlier, crafted grid, iovl, and iden reference graphs can repeatedly decode the same base image because processed_ids is copied per branch and ImageItem::decode_image() has no shared operation budget. This

  • CVE-2026-84446HigSep 18, 2026
    affected < 1.23.4-1.1fixed 1.23.4-1.1

    libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1.23.2, crafted HEIF sequence timing and edit-list data can make Track::init_sample_timing_table() compute a logical m_num_output_samples value that exceeds the uint32_t counters used by Track_Visual::decode_nex

  • CVE-2026-84444HigSep 18, 2026
    affected < 1.23.4-1.1fixed 1.23.4-1.1

    libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1.23.2, when WITH_UNCOMPRESSED_CODEC is enabled, heif_context_add_image_tile() accepts an independently constructed tile whose component-plane dimensions do not match the tile geometry established by the prototy

  • CVE-2026-84384HigSep 18, 2026
    affected < 1.23.4-1.1fixed 1.23.4-1.1

    libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.2, crafted HEIF or AVIF mime metadata and unci image data can cause decompress_brotli() and do_inflate() to grow accumulated output without an effective size limit or MemoryHandle accounting. The b

  • CVE-2026-84383CriSep 18, 2026
    affected < 1.23.4-1.1fixed 1.23.4-1.1

    libheif is a HEIF and AVIF file format decoder and encoder. From 1.22.0 until 1.23.2, a crafted HEIF, HEIC, or AVIF item graph using nested iden and auxl references can make HeifPixelImage::transfer_channel_from_image_as() append duplicate Alpha planes with different bit depths t

  • CVE-2026-62377MedAug 18, 2026
    affected < 1.23.1-1.1fixed 1.23.1-1.1

    libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.0 and earlier, a crafted HEIF sequence accepted by heif_context_read_from_memory() can leave the context with no registered sequence tracks and crash when heif_context_get_track(ctx, 0) is called. HeifContext::ge

  • CVE-2026-62292HigAug 18, 2026
    affected < 1.23.1-1.1fixed 1.23.1-1.1

    libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.1, a crafted uncompressed HEIF image using generic zlib unci full-item compression can crash an application that decodes an advertised tile with heif_image_handle_decode_image_tile(). In libheif/co

  • CVE-2026-62291MedAug 18, 2026
    affected < 1.23.1-1.1fixed 1.23.1-1.1

    libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.0 and earlier, a crafted image sequence with a 2x2 primary plane and a 256x256 auxiliary alpha plane can cause attacker-controlled heap corruption during a normal decode and re-encode workflow. Track_Visual::deco

  • CVE-2026-62289MedAug 18, 2026
    affected < 1.23.1-1.1fixed 1.23.1-1.1

    libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.0 and earlier, a crafted HEIF or AVIF file containing a clean aperture box can reduce an image dimension to zero and crash or corrupt tiling results when heif_image_handle_get_image_tiling(handle, 1, &tiling) is

  • CVE-2026-50142HigAug 18, 2026
    affected < 1.23.0-2.1fixed 1.23.0-2.1

    libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.0, a crafted HEIF sequence accepted by heif_context_read_from_memory() with the msf1 sequence brand can cause unbounded heap allocation. In libheif/sequences/seq_boxes.cc, Box_stsz::parse() applies

  • CVE-2026-48029HigJul 22, 2026
    affected < 1.22.2-1.1fixed 1.22.2-1.1

    libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.19.0 through 1.21.2 have a heap OOB read in ImageItem_Grid::decode_grid_tile via irot-induced tile-coordinate underflow. Version 1.22.0 fixes the issue.

  • CVE-2026-47709MedJul 21, 2026
    affected < 1.22.2-1.1fixed 1.22.2-1.1

    libheif is a HEIF and AVIF file format decoder and encoder. Versions prior to 1.22.0 crashes in the public C API `heif_image_handle_get_image_tiling()` when a malformed uncompressed HEIF image item has an associated `uncC` property but no associated `ispe` property. In debug buil

  • CVE-2026-47254MedJul 21, 2026
    affected < 1.22.2-1.1fixed 1.22.2-1.1

    libheif is a HEIF and AVIF file format decoder and encoder. Prior to version 1.22.0, `Track::init_sample_timing_table()` in `libheif/sequences/track.cc` stores an out-of-bounds chunk index (`m_chunks.size()`) into `m_presentation_timeline` when the number of chunks defined in the

  • CVE-2026-47251MedJul 21, 2026
    affected < 1.22.2-1.1fixed 1.22.2-1.1

    libheif is a HEIF and AVIF file format decoder and encoder. The fix for CVE-2026-3949 (commit `b97c8b5`, PR #1712) introduced an integer overflow in the very security check it added. The check itself can be bypassed, allowing a crafted HEIF file with a VVC track to trigger the sa

  • CVE-2026-47247HigJul 21, 2026
    affected < 1.22.2-1.1fixed 1.22.2-1.1

    libheif is a HEIF and AVIF file format decoder and encoder. Prior to version 1.22.0, two bugs in libheif chain to leak process heap memory as visible pixel values in decoded grid images. An attacker who uploads a crafted AVIF/HEIC file to any server-side image processor (WordPres

  • CVE-2026-47178MedJul 21, 2026
    affected < 1.22.2-1.1fixed 1.22.2-1.1

    libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.19.0 through 1.21.2, a crafted HEIF file (uncompressed `unci` codec, tiled, component-interleaved, 4:2:0) triggers a heap out-of-bounds write in libheif's uncompressed tile decoder. The write overwrites the

  • CVE-2026-47714MedJul 21, 2026
    affected < 1.22.2-1.1fixed 1.22.2-1.1

    libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, the inline mask parsing code in `libheif/region.cc` contains an integer overflow. Both `width` and `height` are `unsigned int` (32-bit) values parsed from the HEIF file. Their product can ex

Page 1 of 2