Search CVE reports


Toggle filters

1 – 10 of 39 results


CVE-2026-62377

Medium priority
Needs evaluation

libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.0 and earlier, a crafted HEIF sequence accepted by heif_context_read_from_memory() can leave the context with no registered sequence tracks and crash when...

1 affected package

libheif

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libheif Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-62291

Medium priority
Needs evaluation

libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.0 and earlier, a crafted image sequence with a 2x2 primary plane and a 256x256 auxiliary alpha plane can cause attacker-controlled heap corruption during a normal...

1 affected package

libheif

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libheif Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-62292

Medium priority
Fixed

Out-of-bounds read in uncompressed unci tile range slicing

1 affected package

libheif

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libheif Fixed Not affected Not affected Not affected Not affected
Show less packages

CVE-2026-62289

Medium priority

Some fixes available 2 of 5

Integer underflow in Fraction constructor via double clap transform application

1 affected package

libheif

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libheif Fixed Fixed Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-47251

Medium priority
Not affected

libheif is a HEIF and AVIF file format decoder and encoder. The fix for CVE-2026-3949 (commit `b97c8b5`, PR #1712) introduced an integer overflow in the very security check it added. The check itself can be bypassed, allowing a...

1 affected package

libheif

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libheif Not affected Not affected Not affected Not affected Not affected
Show less packages

CVE-2026-47247

Medium priority
Fixed

libheif is a HEIF and AVIF file format decoder and encoder. Prior to version 1.22.0, two bugs in libheif chain to leak process heap memory as visible pixel values in decoded grid images. An attacker who uploads a crafted AVIF/HEIC...

1 affected package

libheif

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libheif Fixed Fixed Fixed Fixed Not affected
Show less packages

CVE-2026-50142

Medium priority
Fixed

[Unknown description]

1 affected package

libheif

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libheif Fixed Not affected Not affected Not affected Not affected
Show less packages

CVE-2026-48029

Medium priority
Fixed

libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.19.0 through 1.21.2 have a heap OOB read in ImageItem_Grid::decode_grid_tile via irot-induced tile-coordinate underflow. Version 1.22.0 fixes the issue.

1 affected package

libheif

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libheif Fixed Not affected Not affected Not affected Not affected
Show less packages

CVE-2026-47714

Medium priority
Fixed

libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, the inline mask parsing code in `libheif/region.cc` contains an integer overflow. Both `width` and `height` are `unsigned int` (32-bit)...

1 affected package

libheif

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libheif Fixed Fixed Not affected Not affected Not affected
Show less packages

CVE-2026-47709

Medium priority
Fixed

libheif is a HEIF and AVIF file format decoder and encoder. Versions prior to 1.22.0 crashes in the public C API `heif_image_handle_get_image_tiling()` when a malformed uncompressed HEIF image item has an associated `uncC`...

1 affected package

libheif

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libheif Fixed Fixed Not affected Not affected Not affected
Show less packages