struktur AG libheif是struktur AG组织的一款图像编解码库。 struktur AG libheif 1.23.1之前版本存在安全漏洞,该漏洞源于heif_context_read_from_memory()处理特制HEIF序列时未正确注册序列轨道,导致调用heif_context_get_track(ctx, 0)时触发断言或空指针解引用,造成崩溃。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| strukturag | libheif | < 1.23.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| strukturag | libheif | < 1.23.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-62292 | 8.7 HIGH | libheif: Out-of-bounds read in uncompressed unci tile range slicing |
| CVE-2026-50142 | 7.5 HIGH | libheif: unbounded heap allocation in HEIF sequence parser (stsz fixed-size mode missing b |
| CVE-2026-62291 | 5.3 MEDIUM | libheif: Heap out of bounds write in libheif uncompressed encoder when writing images with |
| CVE-2026-62289 | 4.3 MEDIUM | libheif: Integer underflow in Fraction constructor via double clap transform application |
No comments yet