SUSE-SU-2026:4276-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-20264276-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4276-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/SUSE-SU-2026:4276-1
Upstream
CVE (8)
Related
Published
2026-09-21T09:21:15Z
Modified
2026-09-22T10:30:19Z
Summary
Security update for libheif
Details

This update for libheif fixes the following issues:

  • CVE-2026-84383: Heap buffer overflow in scale_nearest_neighbor() via duplicate alpha planes from nested iden/auxl items (bsc#1279443).
  • CVE-2026-84384: brotli/zlib decompression paths lack output-size limits, allowing decompression-bomb OOM/DoS (bsc#1279445).
  • CVE-2026-84444: Out-of-bounds write in the unci encoder (bsc#1279448).
  • CVE-2026-84446: Sequence decode timing-table initialization allows non-terminating loops and unbounded memory, bypassing max_sequence_frames (bsc#1279447).
  • CVE-2026-84447: Derived-image indirect reference chains and tiled offsets bypass decode caching and MemoryHandle limits, causing CPU/memory amplification DoS (bsc#1279446).
  • CVE-2026-84448: Heap out-of-bounds read in the inline-mask region API (bsc#1279449).
  • CVE-2026-84450: image item with clap property and an ispe declaring a dimension greater than INT32_MAX + 1 can lead to a crash via an abort (bsc#1280002).
  • CVE-2026-84451: crafted HEIF file advertising a 4096 x 4096 uncompressed tile grid can cause an out-of-bounds read due to an integer overflow (bsc#1280001).
  • Out-of-bounds read and write in derived-item and pixel-plane handling (bsc#1279444).

Changes for libheif:

  • Update to version 1.23.4 (jsc#PED-16355)
References

Affected packages

SUSE:Linux Enterprise Module for Desktop Applications 15 SP7
libheif

Package

Name
libheif
Purl
pkg:rpm/suse/libheif&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.23.4-150700.3.21.1

Ecosystem specific

{
    "binaries":  [
        {
            "libheif-aom":  "1.23.4-150700.3.21.1",
            "libheif-dav1d":  "1.23.4-150700.3.21.1",
            "libheif-jpeg":  "1.23.4-150700.3.21.1",
            "libheif-rav1e":  "1.23.4-150700.3.21.1",
            "libheif1":  "1.23.4-150700.3.21.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4276-1.json"
SUSE:Linux Enterprise Module for Package Hub 15 SP7
libheif

Package

Name
libheif
Purl
pkg:rpm/suse/libheif&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.23.4-150700.3.21.1

Ecosystem specific

{
    "binaries":  [
        {
            "gdk-pixbuf-loader-libheif":  "1.23.4-150700.3.21.1",
            "libheif-devel":  "1.23.4-150700.3.21.1",
            "libheif-ffmpeg":  "1.23.4-150700.3.21.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4276-1.json"