openSUSE-SU-2026:21889-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21889-1.json
JSON Data
https://api.osv.dev/v1/vulns/openSUSE-SU-2026:21889-1
Upstream
CVE (8)
Related
Published
2026-09-20T12:44:23Z
Modified
2026-09-25T18:23:11Z
Summary
Security update for libheif
Details

This update for libheif fixes the following issues:

  • CVE-2026-84383: Heap buffer overflow in scale_nearest_neighbor() via duplicate alpha planes from nested iden/auxl items (bsc#1279443).
  • CVE-2026-84384: brotli/zlib decompression paths lack output-size limits, allowing decompression-bomb OOM/DoS (bsc#1279445).
  • CVE-2026-84444: Out-of-bounds write in the unci encoder (bsc#1279448).
  • CVE-2026-84446: Sequence decode timing-table initialization allows non-terminating loops and unbounded memory, bypassing max_sequence_frames (bsc#1279447).
  • CVE-2026-84447: Derived-image indirect reference chains and tiled offsets bypass decode caching and MemoryHandle limits, causing CPU/memory amplification DoS (bsc#1279446).
  • CVE-2026-84448: Heap out-of-bounds read in the inline-mask region API (bsc#1279449).
  • CVE-2026-84450: image item with clap property and an ispe declaring a dimension greater than INT32_MAX + 1 can lead to a crash via an abort (bsc#1280002).
  • CVE-2026-84451: crafted HEIF file advertising a 4096 � 4096 uncompressed tile grid can cause an out-of-bounds read due to an integer overflow (bsc#1280001).
  • Heap out-of-bounds write in the uncompressed encoder for RRGGBB images with interleaved bit-depth <= 8 (bsc#1273083).
  • Out-of-bounds read and write in derived-item and pixel-plane handling (bsc#1279444).

Changes for libheif:

  • Update to version 1.23.4:
  • CVE-2026-XXXXX: The max_items security limit was not enforced for the child boxes of iinf, so a file could declare an unbounded number of items.
  • CVE-2026-XXXXX: Unbounded recursion in the reference-cycle check crashed the parser on a long chain of derived items, without bound when the item-count limit is disabled.
  • CVE-2026-XXXXX: Permanent decoder deadlock through a lock-order inversion in parallel grid tile decoding (enabled by default).
  • CVE-2026-XXXXX: Heap out-of-bounds read in the encoder pluginsi for images whose luma and chroma bit depths differ.
  • CVE-2026-XXXXX: Unreclaimable memory leak in heif_track_get_next_raw_sequence_sample().
  • CVE-2026-XXXXX: Heap out-of-bounds read in the WebCodecs decoder plugin
  • includes fixes from 1.23.3:
  • CVE-2026-XXXXX: Heap buffer overflow (write) in the uncompressed (unci) mixed-interleave decoder when the two chroma components declare different bit depths.
  • CVE-2026-XXXXX: Permanent decoder deadlock through a reference cycle between an image and its alpha auxiliary image.
  • CVE-2026-XXXXX: Heap out-of-bounds read in the YCbCr 4:2:0 to 16-bit interleaved RGB conversion when the chroma planes have a lower bit depth than luma
  • CVE-2026-XXXXX: Heap buffer overflow in the SVT-AV1 encoder plugin when encoding a high-bit-depth alpha channel, and a double free on its send-picture error path.
  • CVE-2026-84451: Incomplete fix: the tile range check of the unci decoder (without icef) could still overflow, allowing an out-of-bounds read
  • CVE-2026-XXXXX: Heap out-of-bounds read when converting odd- height 4:2:0 frames of an uncompressed (uncv) image sequence to RGB.
  • CVE-2026-XXXXX: Out-of-bounds read in the RGB to YCbCr identity- matrix color conversion when the R, G, and B planes have different bit depths
  • CVE-2026-84450: A clap property combined with an oversized ispe reached an assert() in the Fraction arithmetic and aborted the process (incomplete fix). An error is returned instead.
  • Fix Several smaller findings
  • Fix Undefined behavior (negative shift) in the HDR bit-depth up-conversion for target bit depths above 16. Such conversions are now rejected.
  • A number of bug fixes
  • Update to version 1.23.2: [jsc#PED-16355]
  • CVE-2026-84383: Heap buffer overflow in scale_nearest_neighbor() via duplicate alpha planes from nested iden/auxl items. (boo#CVE-2026-84383)
  • Out-of-bounds read and write in derived-item and pixel-plane handling. Through iden and auxl item chains, a crafted file could attach pixel planes whose size differs from the image geometry; crop, scale, and plane-extraction code then indexed those planes with the wrong size. A working code-execution exploit was confirmed. Plane sizes are now validated wherever they are consumed. (boo#1279444)
  • CVE-2026-84384: brotli/zlib decompression of mime metadata and unci image data had no effective output-size limit, so a decompression bomb could exhaust memory. Decompressed output is now bounded by the security limits. (boo#1279445)
  • CVE-2026-84447: Chains of derived-image references (grid, iovl, iden) bypassed decode caching and memory limits, causing CPU and memory amplification. (boo#1279446)
  • CVE-2026-84446: Sequence sample-timing initialization could produce non-terminating decode loops and unbounded memory, bypassing max_sequence_frames. (boo#1279447)
  • CVE-2026-84444: Out-of-bounds write in the unci encoder when heif_context_add_image_tile() is given a tile whose planes do not match its declared size. (boo#1279448)
  • CVE-2026-84448: Heap out-of-bounds read in the inline-mask region API when mask_data_len does not match the region geometry. (boo#1279449)
  • C++ exceptions such as std::bad_alloc can no longer escape the C API read/decode entry points; they are returned as a heif_error instead of aborting the process
  • assert()s in the pixel-image plane allocation were replaced by runtime errors
  • stts/ctts tables describing more samples than the track can have are rejected
  • pclr (JPEG 2000 palette) box: the number of palette entries is bounded by the box size
  • BitReader::skip_bytes() is now constant time (fixes a fuzzer timeout on bogus alignment values)
  • iden items now validate the decoded image size like all other items
  • The uncompressed (unci) encoder rejects images without pixel planes
  • meta, mini, and moov boxes with size 0 (extending to the end of the file) are now parsed correctly
  • Fixed an integer overflow when probing the file size
  • Fixed undefined behavior (signed shift) when reading the NAL unit length in the OpenH264 decoder
  • heif_region_item_add_region_inline_mask_data() now requires non-zero width and height and the mask_data_len must equal the expected (width * height + 7) / 8; otherwise it returns an error instead of storing the mask
  • heif_image_add_plane() returns an error instead of aborting for bit depths outside 1..128 or interleaved component counts outside 1..255
References

Affected packages

openSUSE:Leap 16.0 / libheif

Package

Name
libheif
Purl
pkg:rpm/opensuse/libheif&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.23.4-160000.1.1

Ecosystem specific

{
    "binaries":  [
        {
            "gdk-pixbuf-loader-libheif":  "1.23.4-160000.1.1",
            "libheif-aom":  "1.23.4-160000.1.1",
            "libheif-dav1d":  "1.23.4-160000.1.1",
            "libheif-devel":  "1.23.4-160000.1.1",
            "libheif-ffmpeg":  "1.23.4-160000.1.1",
            "libheif-jpeg":  "1.23.4-160000.1.1",
            "libheif-openh264":  "1.23.4-160000.1.1",
            "libheif-openjpeg":  "1.23.4-160000.1.1",
            "libheif-rav1e":  "1.23.4-160000.1.1",
            "libheif-svtenc":  "1.23.4-160000.1.1",
            "libheif1":  "1.23.4-160000.1.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21889-1.json"