libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.3, the no-icef full-item branch of unc_decoder::get_compressed_image_data_uncompressed() in libheif/codecs/uncompressed/unc_decoder.cc retains an addition-based range check that
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| strukturag | libheif | >= 1.19.0, < 1.23.3 |
affected |
Shenlong is analyzing...
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| strukturag | libheif | >= 1.19.0, < 1.23.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-84383 | 9.8 CRITICAL | libheif: Heap buffer overflow in `scale_nearest_neighbor()` via duplicate Alpha planes fro |
| CVE-2026-84447 | 7.5 HIGH | libheif: Derived-image indirect reference chains and tiled offsets bypass decode caching a |
| CVE-2026-84446 | 7.5 HIGH | libheif: Sequence decode timing-table initialization allows non-terminating loops and unbo |
| CVE-2026-84384 | 7.5 HIGH | libheif: brotli/zlib decompression paths lack output-size limits, allowing decompression-b |
| CVE-2026-84444 | 7.4 HIGH | libheif uncompressed tiled image encoding allows out-of-bounds write |
| CVE-2026-84450 | 4.3 MEDIUM | libheif: `clap` + oversized `ispe` aborts on an assert in `Fraction::Fraction` (incomplete |
| CVE-2026-84448 | 4.0 MEDIUM | libheif: Heap out-of-bounds read in libheif inline-mask region API (heif_region_item_add_r |
| CVE-2026-84449 | 3.7 LOW | libheif hOp_RGB24_32_to_YCbCr Memory Access Error / SEGV |
No comments yet