Posted by Hanno Böck on Sep 19 Hi, Not sure if related, but this very recent commit https://github.com/strukturag/libheif/commit/6ce2bba558a27b63a508e81c085025f91c89899b sounds like it could be security-related and it is not part of the 1.23.4 release. Copying over commit description: --------- Reject in-band coded image sizes over the security limit for all codecs (GHSA-v8qw-hwjv-44hw) A crafted image can declare a small size in its container 'ispe' property while...
Re: Vulnerabilities in libheif and libde265
About this summary. This is a short, independently written summary of an article first published by oss-security. Cyber Security News did not report or verify the underlying story. Read the original: https://seclists.org/oss-sec/2026/q3/841
Source attribution: headline and facts are from oss-security (seclists.org). Summary method: excerpt of the source description. See our source attribution policy.




