SUSE has issued an advisory on April 5: https://lists.suse.com/pipermail/sle-security-updates/2023-April/014381.html The bug link is missing from the advisory, it is here: https://bugzilla.suse.com/show_bug.cgi?id=1208640 The upstream commit that fixed the issue is referenced there. Mageia 8 is also affected.
Whiteboard: (none) => MGA8TOOStatus comment: (none) => Patch available from upstream
Stig looks after libheif, so assigning this to you.
Assignee: bugsquad => smelror
This fix was merged in January and version 1.15.2 was published in March. Hence Cauldron is not affected. Will push an update for MGA8 an a backported fix.
Whiteboard: MGA8TOO => (none)Version: Cauldron => 8Source RPM: libheif-1.15.2-1.mga9.src.rpm => libheif-1.10.0-1.1.mga8.src.rpm
Advisory ======== An upstream patch has been backported to fix CVE-2023-0996. CVE-2023-0996: There is a vulnerability in the strided image data parsing code in the emscripten wrapper for libheif. An attacker could exploit this through a crafted image file to cause a buffer overflow in linear memory during a memcpy call. References ========== https://lists.suse.com/pipermail/sle-security-updates/2023-April/014381.html https://bugzilla.suse.com/show_bug.cgi?id=1208640 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-0996 Files ===== Uploaded to core/updates_testing lib64heif-devel-1.10.0-1.2.mga8 libheif-1.10.0-1.2.mga8 lib64heif1-1.10.0-1.2.mga8 Uploaded to tainted/updates_testing lib64heif-devel-1.10.0-1.2.mga8.tainted libheif-1.10.0-1.2.mga8.tainted lib64heif1-1.10.0-1.2.mga8.tainted from libheif-1.10.0-1.2.mga8.src.rpm
Assignee: smelror => qa-bugs
Status comment: Patch available from upstream => (none)CC: (none) => smelror
No installation issues. Updated the core packages in a VirtualBox "untainted" mga8-64 Plasma guest, after which I was able to load and display a sample heif image, but was not allowed to export into that format. Looks OK there. Updated the tainted packages in another VirtualBox guest. Loaded the same image as above into Gimp, but this time was able to export it to a different folder in the same format. Ok there, too. Validating. Advisory in comment 3.
CC: (none) => andrewsfarm, sysadmin-bugsWhiteboard: (none) => MGA8-64-OKKeywords: (none) => validated_update
Keywords: (none) => advisoryCC: (none) => davidwhodgins
An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2023-0144.html
Status: NEW => RESOLVEDResolution: (none) => FIXED