{"id":"ECHO-912c-d41a-c3c3","summary":"assert(has_sequence()) in HeifContext::get_track(). The whole sequence/\ntrack API arrived in v1.20.0: 1.19.8 has no matches for has_sequence,\nget_track, m_tracks or heif_context_get_track, no libheif/sequences/ and\nno heif_sequences.h, and context.cc is 1572 lines while the upstream\npatch targets line 2115. nm -D on the shipped libheif.so exports no\nsequence/track symbol at all. Same basis as the six entries above. Note\nDebian still lists this open for trixie - the claim rests on the code\nevidence, not their triage.\n","modified":"2026-08-26T10:45:03.746282876Z","published":"2026-08-20T16:16:08.733Z","withdrawn":"2026-08-26T10:15:03.990Z","upstream":["CVE-2026-62377"],"references":[{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2026-62377"},{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2026-62377"}],"affected":[{"package":{"name":"libheif","ecosystem":"Echo","purl":"pkg:deb/echo/libheif"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.19.8-1"}]}],"database_specific":{"source":"https://advisory.echohq.com/osv/ECHO-912c-d41a-c3c3.json"}}],"schema_version":"1.9.0"}