Re: [Buildroot] [PATCH 1/1] package/libheif: security bump version to 1.23.1

Julien Olivain via buildroot <[email protected]> Sat, 25 Jul 2026 11:46:09 +0200
Newsgroups net.busybox.buildroot
Message-ID <[email protected]>
On 24/07/2026 19:21, Bernd Kuhls wrote:
> https://github.com/strukturag/libheif/releases/tag/v1.23.1
> 
> Fixes the following CVEs:
> 
> CVE-2026-62289 (GHSA-jc8f-p23p-5hjg)
> Integer underflow in Fraction constructor via double clap transform
> application
> 
> CVE-2026-62291 (GHSA-xpw3-9rhw-482x)
> Heap out of bounds write in libheif uncompressed encoder when writing
> images with mismatched auxiliary alpha dimensions
> 
> CVE-2026-62292 (GHSA-73p7-m7gg-w2jv)
> Out-of-bounds read in uncompressed unci tile range slicing
> 
> CVE-2026-62377 (GHSA-9ww4-9v47-m7pj)
> Reachable assertion in HeifContext::get_track() aborts on a valid-but-
> empty HEIF sequence file
> 
> (GHSA-46rp-pcq2-rpmr)
> Heap out-of-bounds write in the uncompressed encoder for RRGGBB images
> with interleaved bit-depth ≤ 8
> 
> Signed-off-by: Bernd Kuhls <[email protected]>

Applied to master, thanks.
_______________________________________________
buildroot mailing list
[email protected]
https://lists.buildroot.org/mailman/listinfo/buildroot