libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.19.0 through 1.21.2, a crafted HEIF file (uncompressed `unci` codec, tiled, component-interleaved, 4:2:0) triggers a heap out-of-bounds write in libheif's uncompressed tile decoder. The write overwrites the C++ vtable pointer of an adjacent `unc_decoder_component_interleave` object; the next virtual call dispatches to an attacker-chosen address. Version 1.22.0 patches the issue.
CVSS Details
- CVSS 3.1 Base Score: 6.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Ubuntu | ubuntu-upgrade-heif-gdk-pixbufubuntu-upgrade-heif-thumbnailerubuntu-upgrade-heif-viewubuntu-upgrade-libheif-devubuntu-upgrade-libheif-plugin-aomdecubuntu-upgrade-libheif-plugin-aomencubuntu-upgrade-libheif-plugin-dav1dubuntu-upgrade-libheif-plugin-ffmpegdecubuntu-upgrade-libheif-plugin-j2kdecubuntu-upgrade-libheif-plugin-j2kencubuntu-upgrade-libheif-plugin-jpegdecubuntu-upgrade-libheif-plugin-jpegencubuntu-upgrade-libheif-plugin-kvazaarubuntu-upgrade-libheif-plugin-libde265ubuntu-upgrade-libheif-plugin-rav1eubuntu-upgrade-libheif-plugin-svtencubuntu-upgrade-libheif-plugin-x265ubuntu-upgrade-libheif-plugins-allubuntu-upgrade-libheif1 | Jun 30, 2026 | Jun 29, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub