cbcvebase.
CVE-2025-68431
published 2025-12-29

CVE-2025-68431: libheif is an HEIF and AVIF file format decoder and encoder. Prior to version 1.21.0, a crafted HEIF that exercises the overlay image item path triggers a heap…

PriorityP434high7.1CVSS 3.1
AVNACLPRNUIRSUCLINAH
EPSS
0.27%
18.5th percentile
libheif is an HEIF and AVIF file format decoder and encoder. Prior to version 1.21.0, a crafted HEIF that exercises the overlay image item path triggers a heap buffer over-read in `HeifPixelImage::overlay()`. The function computes a negative row length (likely from an unclipped overlay rectangle or invalid offsets), which then underflows when converted to `size_t` and is passed to `memcpy`, causing a very large read past the end of the source plane and a crash. Version 1.21.0 contains a patch. As a workaround, avoid decoding images using `iovl` overlay boxes.

Affected

9 ranges
VendorProductVersion rangeFixed in
debianlibheif< libheif 1.21.2-1 (forky)libheif 1.21.2-1 (forky)
strukturlibheif< 1.21.01.21.0
strukturlibheif>= 0 < 1.21.2-11.21.2-1
strukturlibheif>= 0 < 1.17.6-1ubuntu4.21.17.6-1ubuntu4.2
strukturlibheif>= 0 < 1.20.2-1ubuntu0.11.20.2-1ubuntu0.1
strukturlibheif>= 0 < 1.1.0-2ubuntu0.1~esm21.1.0-2ubuntu0.1~esm2
strukturlibheif>= 0 < 1.6.1-1ubuntu0.1~esm21.6.1-1ubuntu0.1~esm2
strukturlibheif>= 0 < 1.12.0-2ubuntu0.1~esm21.12.0-2ubuntu0.1~esm2
strukturaglibheif< 1.21.01.21.0

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_debian6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.