Re: Vulnerabilities in libheif and libde265
Hanno Böck flags a security-relevant libheif fix (GHSA-v8qw-hwjv-44hw) rejecting oversized in-band coded image sizes, absent from release 1.23.4.
A follow-up to the libheif/libde265 vulnerability discussion notes that commit 6ce2bba in strukturag/libheif rejects in-band coded image sizes exceeding the security limit for all codecs, tracked as GHSA-v8qw-hwjv-44hw. A crafted image can declare a small size in its container 'ispe' property while the actual coded image is larger, bypassing prior validation. The fix was not included in the libheif 1.23.4 release.