Back Linuxsecurity SUSE libheif Important Heap Buffer Overflow DoS Solved 2026-2622
## This update for libheif fixes the following issues Update to 1.23.0: * CVE-2025-68431: heap buffer over-read in `HeifPixelImage: overlay()` via crafted HEIF that exercises the overlay image item (bsc#1255735). * CVE-2026-3950: manipulation of the component stsz/stts can lead to out-of- bounds read (bsc#1259544). * CVE-2026-32738: Heap OOB Read / SEGV Crash via Zero samples_per_chunk in stsc (bsc#1265874). * CVE-2026-32739: Infinite Loop DoS in stts Sample Duration Lookup (bsc#1265875). * CVE-2026-32740: Heap-Buffer-Overflow Write in Grid Tile Chroma Compositing (bsc#1265876). * CVE-2026-32741: heap buffer overflow in decode_mask_image() (bsc#1265877). * CVE-2026-32814: Uninitialized Heap Memory Information Leak via Failed Grid Tiles (bsc#1265878).
## This update for libheif fixes the following issues Update to 1.23.0: * CVE-2025-68431: heap buffer over-read in `HeifPixelImage: overlay()` via crafted HEIF that exercises the overlay image item (bsc#1255735). * CVE-2026-3950: manipulation of the component stsz/stts can lead to out-of- bounds read (bsc#1259544). * CVE-2026-32738: Heap OOB Read / SEGV Crash via Zero samples_per_chunk in stsc (bsc#1265874). * CVE-2026-32739: Infinite Loop DoS in stts Sample Duration Lookup (bsc#1265875). * CVE-2026-32740: Heap-Buffer-Overflow Write in Grid Tile Chroma Compositing (bsc#1265876). * CVE-2026-32741: heap buffer overflow in decode_mask_image() (bsc#1265877). * CVE-2026-32814: Uninitialized Heap Memory Information Leak via Failed Grid Tiles (bsc#1265878).
* CVE-2025-68431 ( SUSE ): 6.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Announcement ID: SUSE-SU-2026:2622-1 Release Date: 2026-06-24T11:55:37Z Rating: important
Get the latest Linux and open source security news straight to your inbox.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
