Re: [Buildroot] [PATCH 1/1] package/libheif: security bump version to 1.23.1
Julien Olivain via buildroot <[email protected]> Sat, 25 Jul 2026 11:46:09 +0200
| Newsgroups | net.busybox.buildroot |
|---|---|
| Message-ID | <[email protected]> |
On 24/07/2026 19:21, Bernd Kuhls wrote: > https://github.com/strukturag/libheif/releases/tag/v1.23.1 > > Fixes the following CVEs: > > CVE-2026-62289 (GHSA-jc8f-p23p-5hjg) > Integer underflow in Fraction constructor via double clap transform > application > > CVE-2026-62291 (GHSA-xpw3-9rhw-482x) > Heap out of bounds write in libheif uncompressed encoder when writing > images with mismatched auxiliary alpha dimensions > > CVE-2026-62292 (GHSA-73p7-m7gg-w2jv) > Out-of-bounds read in uncompressed unci tile range slicing > > CVE-2026-62377 (GHSA-9ww4-9v47-m7pj) > Reachable assertion in HeifContext::get_track() aborts on a valid-but- > empty HEIF sequence file > > (GHSA-46rp-pcq2-rpmr) > Heap out-of-bounds write in the uncompressed encoder for RRGGBB images > with interleaved bit-depth ≤ 8 > > Signed-off-by: Bernd Kuhls <[email protected]> Applied to master, thanks. _______________________________________________ buildroot mailing list [email protected] https://lists.buildroot.org/mailman/listinfo/buildroot