struktur AG libheif是struktur AG组织的一款图像编解码库。 struktur AG libheif 1.23.1之前版本存在缓冲区错误漏洞,该漏洞源于在解码和重新编码工作流中未检查辅助alpha平面尺寸与主帧匹配,导致越界写入或越界读取,攻击者可通过特制图像序列导致堆损坏。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| strukturag | libheif | < 1.23.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| strukturag | libheif | < 1.23.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-62292 | 8.7 HIGH | libheif: Out-of-bounds read in uncompressed unci tile range slicing |
| CVE-2026-50142 | 7.5 HIGH | libheif: unbounded heap allocation in HEIF sequence parser (stsz fixed-size mode missing b |
| CVE-2026-62289 | 4.3 MEDIUM | libheif: Integer underflow in Fraction constructor via double clap transform application |
| CVE-2026-62377 | 4.3 MEDIUM | libheif: Reachable assertion in HeifContext::get_track() aborts on a valid-but-empty HEIF |
No comments yet