SUSE-SU-2026:3597-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-20263597-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3597-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2026:3597-1
Upstream
CVE (4)
Related
Published
2026-08-12T11:48:46Z
Modified
2026-08-13T09:30:09Z
Summary
Security update for libheif
Details

This update for libheif fixes the following issues:

Update to version 1.23.1 (jsc#PED-16355).

Security issues fixed:

  • CVE-2026-62289: integer underflow in Fraction constructor via double clap transform application (bsc#1273079).
  • CVE-2026-62291: heap out-of-bounds write in the uncompressed encoder when writing images with mismatched auxiliary alpha dimensions (bsc#1273080).
  • CVE-2026-62292: out-of-bounds read in uncompressed unci tile range slicing (bsc#1273081).
  • CVE-2026-62377: reachable assertion in HeifContext::get_track() aborts on a valid-but-empty HEIF sequence file (bsc#1273082).
  • Heap out-of-bounds write in the uncompressed encoder for RRGGBB images with interleaved bit-depth <= 8 (bsc#1273083).

Changes for libheif:

  • Version 1.23.1
    • FFmpeg decoder plugin gains AV1, VVC, JPEG, and JPEG 2000/HTJ2K decoding.
    • SVT-AV1 encoder: new tune=iq and ms-ssim tune parameters.
    • C++ API: added getters/setters for the CLLI and MDCV HDR metadata boxes.
    • Sequence decoder now scales the alpha auxiliary track to the main image size.
    • Fixed pixi box writing for multi-channel images.
    • Corrected the placement of the TAI clock_type field into the top 2 bits.
    • Empty/unset plugin directory is no longer scanned.
References

Affected packages

SUSE:Linux Enterprise Module for Desktop Applications 15 SP7
libheif

Package

Name
libheif
Purl
pkg:rpm/suse/libheif&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.23.1-150700.3.18.1

Ecosystem specific

{
    "binaries":  [
        {
            "libheif-aom":  "1.23.1-150700.3.18.1",
            "libheif-dav1d":  "1.23.1-150700.3.18.1",
            "libheif-jpeg":  "1.23.1-150700.3.18.1",
            "libheif-rav1e":  "1.23.1-150700.3.18.1",
            "libheif1":  "1.23.1-150700.3.18.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3597-1.json"
SUSE:Linux Enterprise Module for Package Hub 15 SP7
libheif

Package

Name
libheif
Purl
pkg:rpm/suse/libheif&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.23.1-150700.3.18.1

Ecosystem specific

{
    "binaries":  [
        {
            "gdk-pixbuf-loader-libheif":  "1.23.1-150700.3.18.1",
            "libheif-devel":  "1.23.1-150700.3.18.1",
            "libheif-ffmpeg":  "1.23.1-150700.3.18.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3597-1.json"