CVE-2026-32740
published 2026-05-19CVE-2026-32740: libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and prior contain a heap-buffer-overflow (write) vulnerability in the grid tile…
PriorityP351high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.51%
40.3th percentile
libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and prior contain a heap-buffer-overflow (write) vulnerability in the grid tile compositing, allowing an attacker to write 64 bytes of fully attacker-controlled data past the end of a chroma plane heap allocation by crafting a HEIF/AVIF file with a 1×4 grid of odd-height tiles. The overflow is triggered during normal image decoding with default build configuration. The written bytes are chroma (Cb/Cr) pixel values from the attacking tile, giving the attacker full control over the overflow content. This issue has been fixed in version 1.22.0.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| struktur | libheif | < 1.22.0 | 1.22.0 |
| strukturag | libheif | < 1.22.0 | 1.22.0 |
| ubuntu | libheif | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
vendor_redhat8.8HIGH
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
libheif vulnerabilities
vendor_ubuntu·2026-06-18·CVSS 6.5
CVE-2026-32740 [MEDIUM] libheif vulnerabilities
Title: libheif vulnerabilities
Summary: Several security issues were fixed in libheif.
Elhanan Haenel discovered that libheif incorrectly handled certain
malformed HEIF sequence files. An attacker could possibly use this
issue to cause a denial of service. This issue only affected Ubuntu 25.10
and Ubuntu 26.04 LTS. (CVE-2026-32738)
Elhanan Haenel discovered that libheif incorrectly handled certain
malformed HEIF sequence files, leading to an infinite loop. An attacker
could possibly use this issue to cause libheif to use excessive
resources, resulting in a denial of service. This issue only affected
Ubuntu 25.10 and Ubuntu 26.04 LTS. (CVE-2026-32739)
Elhanan Haenel discovered that libheif incorrectly handled certain
crafted HEIF/AVIF image files. An attacker could possibly use this iss
Red Hat
libheif: libheif: Arbitrary code execution or denial of service via crafted HEIF/AVIF file
vendor_redhat·2026-05-19·CVSS 8.8
CVE-2026-32740 [HIGH] CWE-787 libheif: libheif: Arbitrary code execution or denial of service via crafted HEIF/AVIF file
libheif: libheif: Arbitrary code execution or denial of service via crafted HEIF/AVIF file
A flaw was found in libheif, a library for decoding and encoding HEIF and AVIF image files. This heap-buffer-overflow vulnerability allows a remote attacker to write arbitrary data beyond the intended memory boundary. By crafting a malicious HEIF/AVIF file with a specific grid tile configuration, an attacker could potentially achieve arbitrary code execution or cause a denial of service.
Package: glycin-loaders (Red Hat Enterprise Linux 10) - Not affected
VulDB
strukturag libheif up to 1.21.x AVIF File out-of-bounds write (GHSA-frfr-f3vg-2g6j)
vuldb·2026-05-19·CVSS 8.8
CVE-2026-32740 [HIGH] strukturag libheif up to 1.21.x AVIF File out-of-bounds write (GHSA-frfr-f3vg-2g6j)
A vulnerability was found in strukturag libheif up to 1.21.x. It has been rated as critical. Impacted is an unknown function of the component AVIF File Handler. The manipulation leads to out-of-bounds write.
This vulnerability is documented as CVE-2026-32740. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is advised.
No detection rules found.
No public exploits indexed.
https://github.com/strukturag/libheif/releases/tag/v1.22.0https://github.com/strukturag/libheif/security/advisories/GHSA-frfr-f3vg-2g6jhttps://access.redhat.com/security/cve/CVE-2026-32740https://bugzilla.redhat.com/show_bug.cgi?id=2479969https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32740.json
2026-05-19
Published