libheif是struktur开源的一款 ISO/IEC 23008-12:2017 HEIF 文件格式解码器和编码器。 libheif 1.21.2及之前版本存在信息泄露漏洞,该漏洞源于解码网格图像时失败瓦片区域未初始化,导致堆内存信息泄露。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| strukturag | libheif | < 1.22.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| strukturag | libheif | < 1.22.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-32740 | 8.8 HIGH | libheif: Heap-Buffer-Overflow Write in Grid Tile Chroma Compositing |
| CVE-2026-32741 | 7.1 HIGH | libheif has a heap buffer overflow in decode_mask_image() |
| CVE-2026-32882 | 7.1 HIGH | libheif: Heap Buffer OOB Read in overlay compositing due to wrong alpha stride |
| CVE-2026-32738 | 6.5 MEDIUM | libheif has a Heap OOB Read/SEGV Crash via Zero samples_per_chunk |
| CVE-2026-32739 | 6.5 MEDIUM | libheif is Vulnerable to Infinite Loop DoS via stts Sample Duration Lookup |
No comments yet