{"id":"SUSE-SU-2026:4276-1","summary":"Security update for libheif","details":"This update for libheif fixes the following issues:\n\n- CVE-2026-84383: Heap buffer overflow in scale_nearest_neighbor() via duplicate alpha planes from nested iden/auxl\n  items (bsc#1279443).\n- CVE-2026-84384: brotli/zlib decompression paths lack output-size limits, allowing decompression-bomb OOM/DoS\n  (bsc#1279445).\n- CVE-2026-84444: Out-of-bounds write in the unci encoder (bsc#1279448).\n- CVE-2026-84446: Sequence decode timing-table initialization allows non-terminating loops and unbounded memory,\n  bypassing max_sequence_frames (bsc#1279447).\n- CVE-2026-84447: Derived-image indirect reference chains and tiled offsets bypass decode caching and MemoryHandle\n  limits, causing CPU/memory amplification DoS (bsc#1279446).\n- CVE-2026-84448: Heap out-of-bounds read in the inline-mask region API (bsc#1279449).\n- CVE-2026-84450: image item with `clap` property and an ispe declaring a dimension greater than `INT32_MAX + 1` can\n  lead to a crash via an abort (bsc#1280002).\n- CVE-2026-84451: crafted HEIF file advertising a 4096 x 4096 uncompressed tile grid can cause an out-of-bounds read due\n  to an integer overflow (bsc#1280001).\n- Out-of-bounds read and write in derived-item and pixel-plane handling (bsc#1279444).\n\nChanges for libheif:\n\n- Update to version 1.23.4 (jsc#PED-16355)\n","modified":"2026-09-22T10:30:19.008973665Z","published":"2026-09-21T09:21:15Z","related":["CVE-2026-84383","CVE-2026-84384","CVE-2026-84444","CVE-2026-84446","CVE-2026-84447","CVE-2026-84448","CVE-2026-84450","CVE-2026-84451"],"upstream":["CVE-2026-84383","CVE-2026-84384","CVE-2026-84444","CVE-2026-84446","CVE-2026-84447","CVE-2026-84448","CVE-2026-84450","CVE-2026-84451"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20264276-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1279443"},{"type":"REPORT","url":"https://bugzilla.suse.com/1279444"},{"type":"REPORT","url":"https://bugzilla.suse.com/1279445"},{"type":"REPORT","url":"https://bugzilla.suse.com/1279446"},{"type":"REPORT","url":"https://bugzilla.suse.com/1279447"},{"type":"REPORT","url":"https://bugzilla.suse.com/1279448"},{"type":"REPORT","url":"https://bugzilla.suse.com/1279449"},{"type":"REPORT","url":"https://bugzilla.suse.com/1280001"},{"type":"REPORT","url":"https://bugzilla.suse.com/1280002"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84383"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84384"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84444"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84446"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84447"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84448"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84450"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84451"}],"affected":[{"package":{"name":"libheif","ecosystem":"SUSE:Linux Enterprise Module for Desktop Applications 15 SP7","purl":"pkg:rpm/suse/libheif&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.23.4-150700.3.21.1"}]}],"ecosystem_specific":{"binaries":[{"libheif1":"1.23.4-150700.3.21.1","libheif-aom":"1.23.4-150700.3.21.1","libheif-dav1d":"1.23.4-150700.3.21.1","libheif-jpeg":"1.23.4-150700.3.21.1","libheif-rav1e":"1.23.4-150700.3.21.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4276-1.json"}},{"package":{"name":"libheif","ecosystem":"SUSE:Linux Enterprise Module for Package Hub 15 SP7","purl":"pkg:rpm/suse/libheif&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.23.4-150700.3.21.1"}]}],"ecosystem_specific":{"binaries":[{"libheif-ffmpeg":"1.23.4-150700.3.21.1","gdk-pixbuf-loader-libheif":"1.23.4-150700.3.21.1","libheif-devel":"1.23.4-150700.3.21.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4276-1.json"}}],"schema_version":"1.9.0"}