libheif是struktur开源的一款 ISO/IEC 23008-12:2017 HEIF 文件格式解码器和编码器。 libheif 1.21.2及之前版本存在缓冲区错误漏洞,该漏洞源于stsc box中samples_per_chunk=0导致无符号整数下溢,映射所有样本到空块,访问时触发段错误,造成拒绝服务。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| strukturag | libheif | < 1.22.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| strukturag | libheif | < 1.22.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-32740 | 8.8 HIGH | libheif: Heap-Buffer-Overflow Write in Grid Tile Chroma Compositing |
| CVE-2026-32741 | 7.1 HIGH | libheif has a heap buffer overflow in decode_mask_image() |
| CVE-2026-32882 | 7.1 HIGH | libheif: Heap Buffer OOB Read in overlay compositing due to wrong alpha stride |
| CVE-2026-32739 | 6.5 MEDIUM | libheif is Vulnerable to Infinite Loop DoS via stts Sample Duration Lookup |
| CVE-2026-32814 | 6.5 MEDIUM | libheif: Uninitialized Heap Memory Information Leak via Failed Grid Tiles |
No comments yet