[ubuntu/noble-security] libheif 1.17.6-1ubuntu4.6 (Accepted)

Kyle Kernick kyle.kernick at canonical.com
Tue Jul 14 16:09:39 UTC 2026


libheif (1.17.6-1ubuntu4.6) noble-security; urgency=medium

  * SECURITY UPDATE: Integer overflow when parsing uncC.
    - debian/patches/CVE-2026-47709.patch: Prevent integer overflow
      when parsing uncC in libheif/uncompressed_image.cc
    - CVE-2026-47709
  * SECURITY UPDATE: Integer overflow in inline mask size calculation
    - debian/patches/CVE-2026-47714.patch: Fix computation of size of inline
      region mask in libheif/region.cc
    - CVE-2026-47714

libheif (1.17.6-1ubuntu4.5) noble; urgency=medium

  * d/p/do-not-stop-with-error-when-items-are-referenced-tha.patch,
    d/p/libheif-support-shared-alpha-thumbnails-and-content-.patch:
    - Backport upstream support for shared auxiliary image references
      (alpha, thumbnails, metadata), fixing "Too many auxiliary image
      references" errors when reading iOS 18 HEIC files. (LP: #2091957)
  * d/p/fix-check-whether-Exif-IFD-table-fits-within-given-m.patch
    - Backport upstream fix for inverted EXIF IFD bounds check that
      prevented the orientation tag from being reset after pixel
      rotation, causing double-rotation in converted images.

Date: 2026-07-13 22:24:12.599573+00:00
Changed-By: Kyle Kernick <kyle.kernick at canonical.com>
https://launchpad.net/ubuntu/+source/libheif/1.17.6-1ubuntu4.6
-------------- next part --------------
Sorry, changesfile not available.


More information about the noble-changes mailing list