This update for libheif fixes the following issues: - CVE-2026-3949: Manipulation of the argument size of a malicious frame can lead to out-of-bounds read (bsc#1259541).