Описание
Security update for libheif
This update for libheif fixes the following issues:
- CVE-2026-3949: Manipulation of the argument size of a malicious frame can lead to out-of-bounds read (bsc#1259541).
Список пакетов
SUSE Linux Enterprise Module for Desktop Applications 15 SP7
libheif-aom-1.19.5-150700.3.8.1
libheif-dav1d-1.19.5-150700.3.8.1
libheif-jpeg-1.19.5-150700.3.8.1
libheif-rav1e-1.19.5-150700.3.8.1
libheif1-1.19.5-150700.3.8.1
SUSE Linux Enterprise Module for Package Hub 15 SP7
gdk-pixbuf-loader-libheif-1.19.5-150700.3.8.1
libheif-devel-1.19.5-150700.3.8.1
libheif-ffmpeg-1.19.5-150700.3.8.1
Ссылки
- Link for SUSE-SU-2026:1660-1
- E-Mail link for SUSE-SU-2026:1660-1
- SUSE Security Ratings
- SUSE Bug 1259541
- SUSE CVE CVE-2026-3949 page
Описание
A vulnerability was determined in strukturag libheif up to 1.21.2. This affects the function vvdec_push_data2 of the file libheif/plugins/decoder_vvdec.cc of the component HEIF File Parser. Executing a manipulation of the argument size can lead to out-of-bounds read. The attack needs to be launched locally. The exploit has been publicly disclosed and may be utilized. This patch is called b97c8b5f198b27f375127cd597a35f2113544d03. It is advisable to implement a patch to correct this issue.
Затронутые продукты
SUSE Linux Enterprise Module for Desktop Applications 15 SP7:libheif-aom-1.19.5-150700.3.8.1
SUSE Linux Enterprise Module for Desktop Applications 15 SP7:libheif-dav1d-1.19.5-150700.3.8.1
SUSE Linux Enterprise Module for Desktop Applications 15 SP7:libheif-jpeg-1.19.5-150700.3.8.1
SUSE Linux Enterprise Module for Desktop Applications 15 SP7:libheif-rav1e-1.19.5-150700.3.8.1
Ссылки
- CVE-2026-3949
- SUSE Bug 1259541