Re: Vulnerabilities in libheif and libde265
libheif 1.23.5 ships security fixes as the underfunded libheif and libde265 project cites 61 advisories.
Hanno Böck told the oss-security list that libheif released version 1.23.5 with various security fixes. The project's September 2026 status note says libheif and libde265 are maintained by one independent developer with almost no recurring funding. That maintainer has had to investigate and fix 61 security advisories. The message links the GitHub release notes but does not list CVE identifiers.
- libheif v1.23.5 includes multiple security fixes.
- libheif and libde265 rely on one independent maintainer.
- The project cites 61 security advisories needing investigation and fixes.
- The posted excerpt does not name individual CVE identifiers.
Posted by Hanno Böck on Sep 22 libheif has released another update with various security fixes: https://github.com/strukturag/libheif/releases/tag/v1.23.5 Pasting the relevant part of the release notes below. I believe this from the project's README is also relevant: "Project status (September 2026). libheif and libde265 are maintained by a single independent developer with almost no recurring funding, while 61 security advisories had to be investigated, fixed and...
This source does not provide full text. Read it at seclists.org.