libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.19.0 through 1.21.2, a crafted HEIF file (uncompressed `unci` codec, tiled, component-interleaved, 4:2:0) triggers a heap out-of-bounds write in libheif's uncompressed tile decoder. The write overwrites the C++ vtable pointer of an adjacent `unc_decoder_component_interleave` object; the next virtual call dispatches to an attacker-chosen address. Version 1.22.0 patches the issue.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade libheif | Aug 9, 2026 | Aug 9, 2026 |
| Ubuntu | — | Upgrade libheif-plugin-aomdecUpgrade libheif-plugin-dav1dUpgrade libheif-plugin-j2kdecUpgrade libheif1Upgrade heif-viewUpgrade libheif-plugin-jpegdecUpgrade libheif-plugin-kvazaarUpgrade libheif-plugin-j2kencUpgrade libheif-plugin-svtencUpgrade libheif-devUpgrade heif-gdk-pixbufUpgrade libheif-plugin-rav1eUpgrade libheif-plugin-x265Upgrade heif-thumbnailerUpgrade libheif-plugin-libde265Upgrade libheif-plugin-jpegencUpgrade libheif-plugin-aomencUpgrade libheif-plugins-allUpgrade libheif-plugin-ffmpegdec | Jun 30, 2026 | Jun 29, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub