{"id":"openSUSE-SU-2026:21889-1","summary":"Security update for libheif","details":"This update for libheif fixes the following issues:\n\n- CVE-2026-84383: Heap buffer overflow in scale_nearest_neighbor() via duplicate alpha planes from nested iden/auxl\n  items (bsc#1279443).\n- CVE-2026-84384: brotli/zlib decompression paths lack output-size limits, allowing decompression-bomb OOM/DoS\n  (bsc#1279445).\n- CVE-2026-84444: Out-of-bounds write in the unci encoder (bsc#1279448).\n- CVE-2026-84446: Sequence decode timing-table initialization allows non-terminating loops and unbounded memory,\n  bypassing max_sequence_frames (bsc#1279447).\n- CVE-2026-84447: Derived-image indirect reference chains and tiled offsets bypass decode caching and MemoryHandle\n  limits, causing CPU/memory amplification DoS (bsc#1279446).\n- CVE-2026-84448: Heap out-of-bounds read in the inline-mask region API (bsc#1279449).\n- CVE-2026-84450: image item with `clap` property and an ispe declaring a dimension greater than `INT32_MAX + 1` can\n  lead to a crash via an abort (bsc#1280002).\n- CVE-2026-84451: crafted HEIF file advertising a 4096 � 4096 uncompressed tile grid can cause an out-of-bounds read due\n  to an integer overflow (bsc#1280001).\n- Heap out-of-bounds write in the uncompressed encoder for RRGGBB images with interleaved bit-depth \u003c= 8 (bsc#1273083).\n- Out-of-bounds read and write in derived-item and pixel-plane handling (bsc#1279444).\n\nChanges for libheif:\n\n- Update to version 1.23.4:\n * CVE-2026-XXXXX: The max_items security limit was not enforced\n for the child boxes of iinf, so a file could declare an\n unbounded number of items.\n * CVE-2026-XXXXX: Unbounded recursion in the reference-cycle\n check crashed the parser on a long chain of derived items,\n without bound when the item-count limit is disabled.\n * CVE-2026-XXXXX: Permanent decoder deadlock through a lock-order\n inversion in parallel grid tile decoding (enabled by default).\n * CVE-2026-XXXXX: Heap out-of-bounds read in the encoder pluginsi\n for images whose luma and chroma bit depths differ.\n * CVE-2026-XXXXX: Unreclaimable memory leak in\n heif_track_get_next_raw_sequence_sample().\n * CVE-2026-XXXXX: Heap out-of-bounds read in the WebCodecs\n decoder plugin\n- includes fixes from 1.23.3:\n * CVE-2026-XXXXX: Heap buffer overflow (write) in the\n uncompressed (unci) mixed-interleave decoder when the two\n chroma components declare different bit depths.\n * CVE-2026-XXXXX: Permanent decoder deadlock through a reference\n cycle between an image and its alpha auxiliary image.\n * CVE-2026-XXXXX: Heap out-of-bounds read in the YCbCr 4:2:0 to\n 16-bit interleaved RGB conversion when the chroma planes have a\n lower bit depth than luma\n * CVE-2026-XXXXX: Heap buffer overflow in the SVT-AV1 encoder\n plugin when encoding a high-bit-depth alpha channel, and a\n double free on its send-picture error path.\n * CVE-2026-84451: Incomplete fix: the tile range check of the\n unci decoder (without icef) could still overflow, allowing an\n out-of-bounds read\n * CVE-2026-XXXXX: Heap out-of-bounds read when converting odd-\n height 4:2:0 frames of an uncompressed (uncv) image sequence to\n RGB.\n * CVE-2026-XXXXX: Out-of-bounds read in the RGB to YCbCr identity-\n matrix color conversion when the R, G, and B planes have\n different bit depths\n * CVE-2026-84450: A clap property combined with an oversized ispe\n reached an assert() in the Fraction arithmetic and aborted the\n process (incomplete fix). An error is returned instead.\n * Fix Several smaller findings\n * Fix Undefined behavior (negative shift) in the HDR bit-depth\n up-conversion for target bit depths above 16. Such conversions\n are now rejected.\n * A number of bug fixes\n- Update to version 1.23.2: [jsc#PED-16355]\n * CVE-2026-84383: Heap buffer overflow in\n scale_nearest_neighbor() via duplicate alpha planes from\n nested iden/auxl items. (boo#CVE-2026-84383)\n * Out-of-bounds read and write in derived-item and pixel-plane\n handling. Through iden and auxl item chains, a crafted file\n could attach pixel planes whose size differs from the image\n geometry; crop, scale, and plane-extraction code then indexed\n those planes with the wrong size. A working code-execution\n exploit was confirmed. Plane sizes are now validated wherever\n they are consumed. (boo#1279444)\n * CVE-2026-84384: brotli/zlib decompression of mime metadata\n and unci image data had no effective output-size limit, so a\n decompression bomb could exhaust memory. Decompressed output\n is now bounded by the security limits. (boo#1279445)\n * CVE-2026-84447: Chains of derived-image references (grid,\n iovl, iden) bypassed decode caching and memory limits, causing\n CPU and memory amplification. (boo#1279446)\n * CVE-2026-84446: Sequence sample-timing initialization could\n produce non-terminating decode loops and unbounded memory,\n bypassing max_sequence_frames. (boo#1279447)\n * CVE-2026-84444: Out-of-bounds write in the unci encoder when\n heif_context_add_image_tile() is given a tile whose planes do\n not match its declared size. (boo#1279448)\n * CVE-2026-84448: Heap out-of-bounds read in the inline-mask\n region API when mask_data_len does not match the region\n geometry. (boo#1279449)\n * C++ exceptions such as std::bad_alloc can no longer escape the\n C API read/decode entry points; they are returned as a\n heif_error instead of aborting the process\n * assert()s in the pixel-image plane allocation were replaced by\n runtime errors\n * stts/ctts tables describing more samples than the track can\n have are rejected\n * pclr (JPEG 2000 palette) box: the number of palette entries is\n bounded by the box size\n * BitReader::skip_bytes() is now constant time (fixes a fuzzer\n timeout on bogus alignment values)\n * iden items now validate the decoded image size like all other\n items\n * The uncompressed (unci) encoder rejects images without pixel\n planes\n * meta, mini, and moov boxes with size 0 (extending to the end of\n the file) are now parsed correctly\n * Fixed an integer overflow when probing the file size\n * Fixed undefined behavior (signed shift) when reading the NAL\n unit length in the OpenH264 decoder\n * heif_region_item_add_region_inline_mask_data() now requires\n non-zero width and height and the mask_data_len must equal\n the expected (width * height + 7) / 8; otherwise it returns\n an error instead of storing the mask\n * heif_image_add_plane() returns an error instead of aborting\n for bit depths outside 1..128 or interleaved component counts\n outside 1..255\n","modified":"2026-09-25T18:23:11.529641806Z","published":"2026-09-20T12:44:23Z","related":["CVE-2026-84383","CVE-2026-84384","CVE-2026-84444","CVE-2026-84446","CVE-2026-84447","CVE-2026-84448","CVE-2026-84450","CVE-2026-84451"],"upstream":["CVE-2026-84383","CVE-2026-84384","CVE-2026-84444","CVE-2026-84446","CVE-2026-84447","CVE-2026-84448","CVE-2026-84450","CVE-2026-84451"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1273083"},{"type":"REPORT","url":"https://bugzilla.suse.com/1279443"},{"type":"REPORT","url":"https://bugzilla.suse.com/1279444"},{"type":"REPORT","url":"https://bugzilla.suse.com/1279445"},{"type":"REPORT","url":"https://bugzilla.suse.com/1279446"},{"type":"REPORT","url":"https://bugzilla.suse.com/1279447"},{"type":"REPORT","url":"https://bugzilla.suse.com/1279448"},{"type":"REPORT","url":"https://bugzilla.suse.com/1279449"},{"type":"REPORT","url":"https://bugzilla.suse.com/1280001"},{"type":"REPORT","url":"https://bugzilla.suse.com/1280002"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84383"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84384"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84444"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84446"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84447"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84448"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84450"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84451"}],"affected":[{"package":{"name":"libheif","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/libheif&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.23.4-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"gdk-pixbuf-loader-libheif":"1.23.4-160000.1.1","libheif-devel":"1.23.4-160000.1.1","libheif-openjpeg":"1.23.4-160000.1.1","libheif-rav1e":"1.23.4-160000.1.1","libheif-svtenc":"1.23.4-160000.1.1","libheif-aom":"1.23.4-160000.1.1","libheif-dav1d":"1.23.4-160000.1.1","libheif-jpeg":"1.23.4-160000.1.1","libheif-ffmpeg":"1.23.4-160000.1.1","libheif1":"1.23.4-160000.1.1","libheif-openh264":"1.23.4-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21889-1.json"}}],"schema_version":"1.9.0"}