Debian Updates libheif for Seven Image-Processing Vulnerabilities

P2 — VALIDATE AND UPDATENot provided by the authority · Not provided by the authorityEXPLOITATION: NOT STATED

Quick Answer

Debian published DSA-6523-1 for libheif in Debian 13 (trixie). Inventory systems and applications that decode HEIF or AVIF images, apply libheif 1.23.4-1~deb13u1, validate image-processing workflows, and retain package and change evidence. Debian does not state a CVSS base score in the advisory.

Confirm Scope And Apply The Supported Fix

What to do now: Locate Debian 13 systems and applications using libheif, identify workflows that process untrusted HEIF or AVIF images, apply libheif 1.23.4-1~deb13u1 from the supported security repository, restart consuming services where required, validate representative image workflows, and preserve package-manager and service evidence.

Open the authoritative advisory

Last verified: 2026-09-28 UTC. Recheck the authoritative advisory and supported distribution channel before changing production.

Scope And Authority

Product scopeDebian 13 (trixie) libheif packages before 1.23.4-1~deb13u1
AdvisoryDSA-6523-1
CVEsCVE-2026-84384, CVE-2026-84444, CVE-2026-84446, CVE-2026-84447, CVE-2026-84448, CVE-2026-84450, CVE-2026-84451
Authoritative release date2026-09-28 08:14:59 UTC (signed Debian security announcement)
Authority revision dateNo separate material revision date stated by Debian; verified against the signed advisory announcement
Affected versionsDebian 13 (trixie) systems and applications using libheif before 1.23.4-1~deb13u1 to process HEIF or AVIF images.
Fixed versionlibheif 1.23.4-1~deb13u1 for Debian 13 (trixie)
CVSS base scoreNot provided by the authority
CVSS severityNot provided by the authority
Exploitation statusNot stated by the authority; no exploitation claim is inferred.

What Changed

Debian corrected seven assigned CVEs and additional upstream-tracked issues in libheif that can cause denial of service, disclose memory, or potentially execute arbitrary code when a malformed image is processed.

What To Validate Now

  1. Inventory. Locate Debian 13 (trixie) systems, containers, and applications with libheif; record package version, repository, image-ingestion paths, exposure to untrusted files, owner, and dependencies.
  2. Establish applicability. Compare the installed package to DSA-6523-1 and the Debian Security Tracker. The advisory addresses the trixie package; do not infer scope for another Debian release, distribution, or upstream build.
  3. Remediate. Install libheif 1.23.4-1~deb13u1 through a supported Debian security repository, following Debian's current advisory and normal change control.
  4. Validate. Confirm the installed package version, restart or reload long-running consumers where required, exercise representative HEIF and AVIF decode and encode workflows, monitor for regressions, and retain package and validation evidence.
  5. Retain evidence. Preserve asset and owner identifiers, the applicability decision, before-and-after versions, change approval, installation output, validation results, and any exception or rollback record.

Operational Cautions

Malformed image processing may occur through user uploads, document conversion, thumbnails, messaging, or other indirect paths. Test dependent applications and capacity-sensitive workflows; severity is not evidence of exploitation.

Evidence To Retain

  • Exact product, release stream, package or application version, enabled feature, environment, and accountable owner.
  • UTC timestamps, authority revision, approved change record, installer or package-manager output, and resulting version.
  • Relevant logs and monitoring evidence, test results, exceptions, compensating controls, and rollback decisions.

Related TechGeeks Resources

Authoritative References

Correction policy: If the authority changes affected versions, fixed versions, severity, exploitation information, mitigations, or required action, TechGeeks will update this notice and its verification date.