DSA-6417-1 libheif - security update
Multiple security issues were discovered in libheif, an ISO/IEC 23008-12 HEIF and AVIF image file format decoder and encoder, which may result in denial of service, the disclosure of sensitive memory contents or, potentially, the execution of arbitrary code if a malformed image file is processed. Note that in the fix for CVE-2026-47178, a heap out-of-bounds write in the uncompressed tile decoder, the affected format combinations are now rejected with heif_error_Unsupported_feature: uncompressed images with 4:2:0 or 4:2:2 chroma subsampling that are tiled, or that use row or pixel interleave. Upstream corrected the offending arithmetic, but only after a restructuring of the uncompressed decoder that is not present in the version shipped in the stable distribution. Images in these configurations will no longer decode. https://security-tracker.debian.org/tracker/DSA-6417-1
CSIRTS triage
- What
- Multiple security issues in HEIF/AVIF image decoder including heap out-of-bounds write in uncompressed tile decoder, potentially allowing arbitrary code execution, denial of service, or sensitive memory disclosure.
- Who is affected
- Any deployment processing untrusted HEIF or AVIF image files with libheif.
- Urgency
- High priority due to potential remote code execution when processing malformed image files.
- Action
- Apply Debian security update DSA-6417-1 to libheif; note that certain image configurations (uncompressed 4:2:0 or 4:2:2 chroma subsampling with tiling or interleave) will no longer decode after the fix.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch libheif
Get an email when a new libheif advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://lists.debian.org/debian-security-announce/2026/msg00328.html
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-471780.20% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 10% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-47178 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
More from Debian Security Advisories
- unknownDSA-6467-1 freecad - security update2026-08-26
- unknownDSA-6468-1 emacs - security update2026-08-26
- unknownDSA-6465-1 openssl - security update2026-08-25
- unknownDSA-6466-1 linux - security update2026-08-25
- unknownDSA-6464-1 erlang - security update2026-08-25