Home / mailings [SECURITY] [DSA 6523-1] libheif security update
Posted on 28 September 2026
Debian Security Advisory- -------------------------------------------------------------------------
Debian Security Advisory DSA-6523-1 security@debian.org
https://www.debian.org/security/ Aron Xu
September 28, 2026 https://www.debian.org/security/faq
- -------------------------------------------------------------------------
Package : libheif
CVE ID : CVE-2026-84384 CVE-2026-84444 CVE-2026-84446 CVE-2026-84447
CVE-2026-84448 CVE-2026-84450 CVE-2026-84451
Multiple security issues were discovered in libheif, an ISO/IEC 23008-12
HEIF and AVIF image file format decoder and encoder, which may result in
denial of service, the disclosure of sensitive memory contents or,
potentially, the execution of arbitrary code if a malformed image file is
processed.
Besides the CVEs listed above, this update also fixes a number of issues
tracked upstream as GHSA-x8r2-mggj-j6wr, GHSA-w7mc-p8jc-p853,
GHSA-9rj8-5mp5-26c9, GHSA-4jqm-2x34-6f6r, GHSA-vg7w-rp49-4fc2,
GHSA-5w8x-856j-7x7c, GHSA-fqpw-fj22-78w4, GHSA-prgh-72vc-3xmc,
GHSA-xrp2-63fq-jm8q, GHSA-4rv4-953r-p24q and GHSA-rhgw-q5g8-xjh2, and had
no CVE assigned when this advisory was published.
For the stable distribution (trixie), these problems have been fixed in
version 1.23.4-1~deb13u1.
We recommend that you upgrade your libheif packages.
For the detailed security status of libheif please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/libheif
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/
Mailing list: debian-security-announce@lists.debian.org
