USN-8846-1: libheif vulnerabilities
Ubuntu USN-8846-1 patches libheif flaws allowing remote denial of service via crafted metadata and HEIF data.
Ubuntu Security Notice USN-8846-1 fixes multiple libheif vulnerabilities discovered by Yuqi Qiu and Xiang Li. CVE-2026-84384 involves incorrect handling of compressed metadata and affects Ubuntu 24.04 LTS and 26.04 LTS; CVE-2026-84446 involves incorrect HEIF sequence data handling and affects Ubuntu 26.04 LTS. A further flaw in image reference handling also enables remote denial of service. All issues could allow a remote attacker to crash applications processing malicious HEIF files.
- CVE-2026-84384: compressed metadata DoS, affects Ubuntu 24.04 LTS and 26.04 LTS
- CVE-2026-84446: HEIF sequence data DoS, affects Ubuntu 26.04 LTS
- Remote denial of service only; no code execution indicated
Vulnerabilities mentionedAll →
- CVE-2026-843847.5—Unbounded decompression memory DoS in libheif HEIF/AVIF decoder 1.19.0-1.23.1published · struktur AG (libheif project) libheif
- CVE-2026-844467.5—Infinite-loop DoS in libheif HEIF/AVIF decoder before 1.23.2published · strukturag libheif
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected |
|---|
Yuqi Qiu and Xiang Li discovered that libheif incorrectly handled certain compressed metadata. A remote attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-84384) Yuqi Qiu and Xiang Li discovered that libheif incorrectly handled certain HEIF sequence data. A remote attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-84446) Yuqi Qiu and Xiang Li discovered that libheif incorrectly handled certain image references. A remote attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 26.04…
This source does not provide full text. Read it at ubuntu.com.