Amazon Linux 2023 Security Advisory: ALAS2023-2026-1971
Advisory Released Date: 2026-07-20
Advisory Updated Date: 2026-07-20
FAQs regarding Amazon Linux ALAS/CVE Severity
Heap Information Disclosure via Grid Image Gap + Uninitialized Pixel Plane Allocation (CVE-2026-47247)
libheif crashes in the public C API heif_image_handle_get_image_tiling() when a malformed uncompressed HEIF image item has an associated uncC property but no associated ispe property. In debug builds this trips the ispe && uncC assertion in ImageItem_uncompressed::get_heif_image_tiling(). In a release/NDEBUG ASan build, the same file causes a null pointer read at address 0xa8. (CVE-2026-47709)
Integer overflow in inline mask size calculation causes undersized buffer allocation (CVE-2026-47714)
heap OOB read in ImageItem_Grid::decode_grid_tile via irot-induced tile-coordinate underflow (CVE-2026-48029)
Affected Packages:
libheif
Issue Correction:
Run dnf update libheif --releasever 2023.12.20260720 or dnf update --advisory ALAS2023-2026-1971 --releasever 2023.12.20260720 to update your system.
More information on how to update your system can be found on this page: Amazon Linux 2023 documentation
aarch64:
libheif-debuginfo-1.19.8-1.amzn2023.0.7.aarch64
heif-pixbuf-loader-debuginfo-1.19.8-1.amzn2023.0.7.aarch64
libheif-debugsource-1.19.8-1.amzn2023.0.7.aarch64
libheif-devel-1.19.8-1.amzn2023.0.7.aarch64
libheif-tools-debuginfo-1.19.8-1.amzn2023.0.7.aarch64
heif-pixbuf-loader-1.19.8-1.amzn2023.0.7.aarch64
libheif-1.19.8-1.amzn2023.0.7.aarch64
libheif-tools-1.19.8-1.amzn2023.0.7.aarch64
src:
libheif-1.19.8-1.amzn2023.0.7.src
x86_64:
libheif-debuginfo-1.19.8-1.amzn2023.0.7.x86_64
libheif-tools-debuginfo-1.19.8-1.amzn2023.0.7.x86_64
libheif-debugsource-1.19.8-1.amzn2023.0.7.x86_64
heif-pixbuf-loader-debuginfo-1.19.8-1.amzn2023.0.7.x86_64
heif-pixbuf-loader-1.19.8-1.amzn2023.0.7.x86_64
libheif-tools-1.19.8-1.amzn2023.0.7.x86_64
libheif-1.19.8-1.amzn2023.0.7.x86_64
libheif-devel-1.19.8-1.amzn2023.0.7.x86_64