libheif is a HEIF and AVIF file format decoder and encoder. Prior to version 1.22.1, the uncompressed HEIF decoder validates explicit icef compressed-unit offsets using unit_offset + unit_size. Because the addition can wrap, a crafted HEIF file can pass the range check and then construct a vector from iterators outside the compressed item buffer, producing an out-of-bounds heap read and crash. Version 1.22.1 patches the issue.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux_2023 | — | Upgrade libheif-toolsUpgrade libheif-debugsourceUpgrade libheif-develUpgrade libheifUpgrade libheif-tools-debuginfoUpgrade heif-pixbuf-loaderUpgrade heif-pixbuf-loader-debuginfoUpgrade libheif-debuginfo | Jul 8, 2026 | Jun 19, 2026 |
| Debian | — | Upgrade libheif | Aug 9, 2026 | Aug 9, 2026 |
| Ubuntu | — | Upgrade libheif-plugin-x265Upgrade libheif-plugin-jpegencUpgrade libheif-plugin-svtencUpgrade libheif-plugin-j2kdecUpgrade heif-viewUpgrade libheif-devUpgrade libheif-plugin-aomdecUpgrade heif-gdk-pixbufUpgrade heif-thumbnailerUpgrade libheif-plugin-ffmpegdecUpgrade libheif1Upgrade libheif-plugin-rav1eUpgrade libheif-plugin-jpegdecUpgrade libheif-plugins-allUpgrade libheif-plugin-libde265Upgrade libheif-plugin-j2kencUpgrade libheif-plugin-dav1dUpgrade libheif-plugin-aomencUpgrade libheif-plugin-kvazaar | Jun 30, 2026 | Jun 29, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub