package/libheif: security bump version to 1.23.1

https://github.com/strukturag/libheif/releases/tag/v1.23.1

Fixes the following CVEs:

CVE-2026-62289 (GHSA-jc8f-p23p-5hjg)
Integer underflow in Fraction constructor via double clap transform
application

CVE-2026-62291 (GHSA-xpw3-9rhw-482x)
Heap out of bounds write in libheif uncompressed encoder when writing
images with mismatched auxiliary alpha dimensions

CVE-2026-62292 (GHSA-73p7-m7gg-w2jv)
Out-of-bounds read in uncompressed unci tile range slicing

CVE-2026-62377 (GHSA-9ww4-9v47-m7pj)
Reachable assertion in HeifContext::get_track() aborts on a valid-but-
empty HEIF sequence file

(GHSA-46rp-pcq2-rpmr)
Heap out-of-bounds write in the uncompressed encoder for RRGGBB images
with interleaved bit-depth ≤ 8

Signed-off-by: Bernd Kuhls <bernd@kuhls.net>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit bcb48623fa)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
This commit is contained in:
Bernd Kuhls
2026-07-24 19:21:24 +02:00
committed by Thomas Perale
parent b46e9ed92f
commit cba956e327
2 changed files with 3 additions and 3 deletions

View File

@@ -1,4 +1,4 @@
# From https://github.com/strukturag/libheif/releases/tag/v1.23.0
sha256 4c9182b18897617182eed12ab5eb9f9d855b3aa3a736d6bdb31abc034ec7d393 libheif-1.23.0.tar.gz
# From https://github.com/strukturag/libheif/releases/tag/v1.23.1
sha256 0de0327f60fcd47de90d5654c6fe152232738d60d84fe084ec3e0f35e03b166a libheif-1.23.1.tar.gz
# Locally computed:
sha256 fa81ce652315b013359d6e8e4744335f31a50c7c192907176d3632f78a3b4596 COPYING

View File

@@ -4,7 +4,7 @@
#
################################################################################
LIBHEIF_VERSION = 1.23.0
LIBHEIF_VERSION = 1.23.1
LIBHEIF_SITE = https://github.com/strukturag/libheif/releases/download/v$(LIBHEIF_VERSION)
LIBHEIF_LICENSE = LGPL-3.0+
LIBHEIF_LICENSE_FILES = COPYING