A vulnerability was determined in strukturag libheif up to 1.21.2. This affects the function vvdec_push_data2 of the file libheif/plugins/decoder_vvdec.cc of the component HEIF File Parser. Executing a manipulation of the argument size can lead to out-of-bounds read. The attack needs to be launched locally. The exploit has been publicly disclosed and may be utilized. This patch is called b97c8b5f198b27f375127cd597a35f2113544d03. It is advisable to implement a patch to correct this issue.
CVSS Details
- CVSS 4.0 Base Score: 1.9 (LOW)
- CVSS 4.0 Vector: (CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
- CVSS 3.1 Base Score: 3.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux_2023 | — | Upgrade libheif-debuginfoUpgrade heif-pixbuf-loaderUpgrade libheif-tools-debuginfoUpgrade libheif-debugsourceUpgrade heif-pixbuf-loader-debuginfoUpgrade libheif-develUpgrade libheif-toolsUpgrade libheif | Apr 7, 2026 | Mar 11, 2026 |
| Suse | — | Upgrade libheif-dav1dUpgrade libheif-aomUpgrade libheif-svtencUpgrade libheif-develUpgrade libheif-rav1eUpgrade libheif-jpegUpgrade libheif-openh264Upgrade gdk-pixbuf-loader-libheifUpgrade libheif-ffmpegUpgrade libheif-openjpegUpgrade libheif1 | May 4, 2026 | Apr 29, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub