Debian Updates libheif for Seven Image-Processing Vulnerabilities
Quick Answer
Debian published DSA-6523-1 for libheif in Debian 13 (trixie). Inventory systems and applications that decode HEIF or AVIF images, apply libheif 1.23.4-1~deb13u1, validate image-processing workflows, and retain package and change evidence. Debian does not state a CVSS base score in the advisory.
Confirm Scope And Apply The Supported Fix
What to do now: Locate Debian 13 systems and applications using libheif, identify workflows that process untrusted HEIF or AVIF images, apply libheif 1.23.4-1~deb13u1 from the supported security repository, restart consuming services where required, validate representative image workflows, and preserve package-manager and service evidence.
Last verified: 2026-09-28 UTC. Recheck the authoritative advisory and supported distribution channel before changing production.
Scope And Authority
| Product scope | Debian 13 (trixie) libheif packages before 1.23.4-1~deb13u1 |
|---|---|
| Advisory | DSA-6523-1 |
| CVEs | CVE-2026-84384, CVE-2026-84444, CVE-2026-84446, CVE-2026-84447, CVE-2026-84448, CVE-2026-84450, CVE-2026-84451 |
| Authoritative release date | 2026-09-28 08:14:59 UTC (signed Debian security announcement) |
| Authority revision date | No separate material revision date stated by Debian; verified against the signed advisory announcement |
| Affected versions | Debian 13 (trixie) systems and applications using libheif before 1.23.4-1~deb13u1 to process HEIF or AVIF images. |
| Fixed version | libheif 1.23.4-1~deb13u1 for Debian 13 (trixie) |
| CVSS base score | Not provided by the authority |
| CVSS severity | Not provided by the authority |
| Exploitation status | Not stated by the authority; no exploitation claim is inferred. |
What Changed
Debian corrected seven assigned CVEs and additional upstream-tracked issues in libheif that can cause denial of service, disclose memory, or potentially execute arbitrary code when a malformed image is processed.
What To Validate Now
- Inventory. Locate Debian 13 (trixie) systems, containers, and applications with libheif; record package version, repository, image-ingestion paths, exposure to untrusted files, owner, and dependencies.
- Establish applicability. Compare the installed package to DSA-6523-1 and the Debian Security Tracker. The advisory addresses the trixie package; do not infer scope for another Debian release, distribution, or upstream build.
- Remediate. Install libheif 1.23.4-1~deb13u1 through a supported Debian security repository, following Debian's current advisory and normal change control.
- Validate. Confirm the installed package version, restart or reload long-running consumers where required, exercise representative HEIF and AVIF decode and encode workflows, monitor for regressions, and retain package and validation evidence.
- Retain evidence. Preserve asset and owner identifiers, the applicability decision, before-and-after versions, change approval, installation output, validation results, and any exception or rollback record.
Operational Cautions
Malformed image processing may occur through user uploads, document conversion, thumbnails, messaging, or other indirect paths. Test dependent applications and capacity-sensitive workflows; severity is not evidence of exploitation.
Evidence To Retain
- Exact product, release stream, package or application version, enabled feature, environment, and accountable owner.
- UTC timestamps, authority revision, approved change record, installer or package-manager output, and resulting version.
- Relevant logs and monitoring evidence, test results, exceptions, compensating controls, and rollback decisions.
Related TechGeeks Resources
Authoritative References
Correction policy: If the authority changes affected versions, fixed versions, severity, exploitation information, mitigations, or required action, TechGeeks will update this notice and its verification date.

