libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.19.0 through 1.21.2, a crafted HEIF file (uncompressed `unci` codec, tiled, component-interleaved, 4:2:0) triggers a heap out-of-bounds write in libheif's uncompressed tile decoder. The write overwrites the C++ vtable pointer of an adjacent `unc_decoder_component_interleave` object; the next virtual call dispatches to an attacker-chosen address. Version 1.22.0 patches the issue.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade libheif | Aug 9, 2026 | Aug 9, 2026 |
| Ubuntu | — | Upgrade heif-viewUpgrade libheif-plugin-jpegdecUpgrade libheif1Upgrade libheif-plugin-kvazaarUpgrade libheif-plugin-j2kdecUpgrade libheif-plugin-aomdecUpgrade libheif-plugin-j2kencUpgrade heif-gdk-pixbufUpgrade libheif-plugin-dav1dUpgrade libheif-plugin-svtencUpgrade libheif-plugin-rav1eUpgrade libheif-devUpgrade libheif-plugin-jpegencUpgrade libheif-plugin-ffmpegdecUpgrade libheif-plugins-allUpgrade libheif-plugin-aomencUpgrade heif-thumbnailerUpgrade libheif-plugin-libde265Upgrade libheif-plugin-x265 | Jun 30, 2026 | Jun 29, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub