libheif是struktur开源的一款 ISO/IEC 23008-12:2017 HEIF 文件格式解码器和编码器。 libheif 1.21.2及之前版本存在安全漏洞,该漏洞源于Box_stts::get_sample_duration()中无限循环,消耗100% CPU,导致拒绝服务。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| strukturag | libheif | < 1.22.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| strukturag | libheif | < 1.22.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-32740 | 8.8 HIGH | libheif: Heap-Buffer-Overflow Write in Grid Tile Chroma Compositing |
| CVE-2026-32741 | 7.1 HIGH | libheif has a heap buffer overflow in decode_mask_image() |
| CVE-2026-32882 | 7.1 HIGH | libheif: Heap Buffer OOB Read in overlay compositing due to wrong alpha stride |
| CVE-2026-32738 | 6.5 MEDIUM | libheif has a Heap OOB Read/SEGV Crash via Zero samples_per_chunk |
| CVE-2026-32814 | 6.5 MEDIUM | libheif: Uninitialized Heap Memory Information Leak via Failed Grid Tiles |
No comments yet