HEIF and AVIF image file format decoder and encoder, which may result in
denial of service, the disclosure of sensitive memory contents or,
potentially, the execution of arbitrary code if a malformed image file is
processed.
Note that in the fix for CVE-2026-47178, a heap out-of-bounds write in the
uncompressed tile decoder, the affected format combinations are now rejected
with heif_error_Unsupported_feature: uncompressed images with 4:2:0 or 4:2:2
chroma subsampling that are tiled, or that use row or pixel interleave.
Upstream corrected the offending arithmetic, but only after a restructuring
of the uncompressed decoder that is not present in the version shipped in
the stable distribution. Images in these configurations will no longer
decode.
https://security-tracker.debian.org/tracker/DSA-6417-1
SOCIAL SHARE CARD GENERATOR