Ubuntu alert USN-8479-1 (libheif)
| From: | noreply+usn-bot--- via ubuntu-security-announce <ubuntu-security-announce@lists.ubuntu.com> | |
| To: | ubuntu-security-announce@lists.ubuntu.com | |
| Subject: | [USN-8479-1] libheif vulnerabilities | |
| Date: | Mon, 29 Jun 2026 18:36:59 +0000 | |
| Message-ID: | <E1weGqp-0008Tv-KW@lists.ubuntu.com> | |
| Cc: | noreply+usn-bot@canonical.com |
========================================================================== Ubuntu Security Notice USN-8479-1 June 29, 2026 libheif vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 25.10 Summary: Several security issues were fixed in libheif. Software Description: - libheif: An ISO/IEC 23008-12:2017 HEIF and AVIF file format decoder and encoder Details: It was discovered that libheif incorrectly handled certain crafted HEIF files. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-47178) It was discovered that libheif incorrectly validated offsets when decoding certain crafted HEIF files. An attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-49271) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS heif-gdk-pixbuf 1.21.2-3ubuntu0.2 heif-thumbnailer 1.21.2-3ubuntu0.2 heif-view 1.21.2-3ubuntu0.2 libheif-dev 1.21.2-3ubuntu0.2 libheif-plugin-aomdec 1.21.2-3ubuntu0.2 libheif-plugin-aomenc 1.21.2-3ubuntu0.2 libheif-plugin-dav1d 1.21.2-3ubuntu0.2 libheif-plugin-ffmpegdec 1.21.2-3ubuntu0.2 libheif-plugin-j2kdec 1.21.2-3ubuntu0.2 libheif-plugin-j2kenc 1.21.2-3ubuntu0.2 libheif-plugin-jpegdec 1.21.2-3ubuntu0.2 libheif-plugin-jpegenc 1.21.2-3ubuntu0.2 libheif-plugin-kvazaar 1.21.2-3ubuntu0.2 libheif-plugin-libde265 1.21.2-3ubuntu0.2 libheif-plugin-rav1e 1.21.2-3ubuntu0.2 libheif-plugin-svtenc 1.21.2-3ubuntu0.2 libheif-plugin-x265 1.21.2-3ubuntu0.2 libheif-plugins-all 1.21.2-3ubuntu0.2 libheif1 1.21.2-3ubuntu0.2 Ubuntu 25.10 heif-gdk-pixbuf 1.20.2-1ubuntu0.5 heif-thumbnailer 1.20.2-1ubuntu0.5 heif-view 1.20.2-1ubuntu0.5 libheif-dev 1.20.2-1ubuntu0.5 libheif-plugin-aomdec 1.20.2-1ubuntu0.5 libheif-plugin-aomenc 1.20.2-1ubuntu0.5 libheif-plugin-dav1d 1.20.2-1ubuntu0.5 libheif-plugin-ffmpegdec 1.20.2-1ubuntu0.5 libheif-plugin-j2kdec 1.20.2-1ubuntu0.5 libheif-plugin-j2kenc 1.20.2-1ubuntu0.5 libheif-plugin-jpegdec 1.20.2-1ubuntu0.5 libheif-plugin-jpegenc 1.20.2-1ubuntu0.5 libheif-plugin-kvazaar 1.20.2-1ubuntu0.5 libheif-plugin-libde265 1.20.2-1ubuntu0.5 libheif-plugin-rav1e 1.20.2-1ubuntu0.5 libheif-plugin-svtenc 1.20.2-1ubuntu0.5 libheif-plugin-x265 1.20.2-1ubuntu0.5 libheif-plugins-all 1.20.2-1ubuntu0.5 libheif1 1.20.2-1ubuntu0.5 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8479-1 CVE-2026-47178, CVE-2026-49271 Package Information: https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubun... https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubun...
Attachment: signature.asc (type=application/pgp-signature)
-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmpCuwsACgkQcpJm3tlz hgFXPhAAnzh0WLtBoiTr/qxvefZl12GCJarJ+BcI0ws0FHKebX0lB8xWGYrLv0Jy Z4lsZXG5j2buhBG7nDSxtGPv0Xalk92FyHfesW6tdg4MLBhrK1OQRLHu7vMVDKyO WGGKxAAoQt9UDsrbN661TZFwhSJvKnhSIS6I9ammA7hC8RbmJQE+fCL54LhV0CEQ V0SS5XVKnl0ew0v5iK/2tAUqX2Fwc3cz5c+puRd/jvAISZFn2x2kCZ9USW/jqnmQ 7iUx9u4ljTLJ+3RJhj621o+oMshVd7p2cBBR/an/mbTARNzuA0mrKRCY4KN3go/2 ZRwYB3ON/Zpb+VNUFiLXjk96ia3plzaYbtVfgRyQdfgPL8VI9mY7u6FYtGvN/Dhs cpUvZQtrYaJ5GKJ9pA7/KE233M+68jHW16OqAUKCc6O6MaLxmOj3cC4borAL937y dD+8Unzrskv9NuZ47hoJGuUDhrXZ75g2+TIjTKGOFyBV6YUJnCpbTi/0P+d2JLb6 E05l/KPER/rMmQtNukcBIKATzgynDcx1e9wws0AEo3na8LRi0pAa0bHc6L+7A0gI 19tdZSa4oyGd/TfVl7cE/XoKmk9JMAtwEBuHugTTCW5wKCyPSw02Ypjlm/7EcBSv keUOBudwXEo1h0G7pDpY8Dm6lO0y5YqO1YaE5JOF9EPwgW63brU= =OgE+ -----END PGP SIGNATURE-----
