CVE-2026-32882
published 2026-05-19CVE-2026-32882: libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and prior contain a heap buffer over-read in HeifPixelImage::overlay() in…
PriorityP434high7.1CVSS 3.1
AVNACLPRNUIRSUCLINAH
EPSS
0.32%
24.7th percentile
libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and prior contain a heap buffer over-read in HeifPixelImage::overlay() in libheif/pixelimage.cc. When compositing an overlay image (iovl) whose child image has a different bit depth for the alpha channel than for the color channels, the function indexes into the alpha plane using the color channel stride (in_stride) instead of the previously retrieved alpha_stride, causing reads past the end of the alpha buffer (up to 3,123 bytes for a 100×50 image with 10-bit color and 8-bit alpha). A crafted HEIF file can exploit this to cause a denial of service (crash) or potentially disclose adjacent heap memory through leaked bytes embedded in the decoded output pixels. This issue has been fixed in versionThis issue has been fixed in version 1.22.0.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| strukturag | libheif | < 1.22.0 | 1.22.0 |
| ubuntu | libheif | — | — |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H
vendor_redhat7.1HIGH
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
libheif vulnerabilities
vendor_ubuntu·2026-06-18·CVSS 6.5
CVE-2026-32740 [MEDIUM] libheif vulnerabilities
Title: libheif vulnerabilities
Summary: Several security issues were fixed in libheif.
Elhanan Haenel discovered that libheif incorrectly handled certain
malformed HEIF sequence files. An attacker could possibly use this
issue to cause a denial of service. This issue only affected Ubuntu 25.10
and Ubuntu 26.04 LTS. (CVE-2026-32738)
Elhanan Haenel discovered that libheif incorrectly handled certain
malformed HEIF sequence files, leading to an infinite loop. An attacker
could possibly use this issue to cause libheif to use excessive
resources, resulting in a denial of service. This issue only affected
Ubuntu 25.10 and Ubuntu 26.04 LTS. (CVE-2026-32739)
Elhanan Haenel discovered that libheif incorrectly handled certain
crafted HEIF/AVIF image files. An attacker could possibly use this iss
Red Hat
libheif: libheif: Denial of Service and Information Disclosure vulnerability
vendor_redhat·2026-05-19·CVSS 7.1
CVE-2026-32882 [HIGH] CWE-125 libheif: libheif: Denial of Service and Information Disclosure vulnerability
libheif: libheif: Denial of Service and Information Disclosure vulnerability
A flaw was found in libheif, a library used for handling High Efficiency Image File Format (HEIF) and AV1 Image File Format (AVIF) images. A remote attacker could exploit a heap buffer over-read vulnerability by providing a specially crafted HEIF file. This could lead to a denial of service, causing the application to crash, or potentially disclose sensitive information from adjacent memory through the decoded output pixels.
Package: glycin-loaders (Red Hat Enterprise Linux 10) - Not affected
VulDB
strukturag libheif up to 1.21.x libheif/pixelimage.cc HeifPixelImage::overlay out-of-bounds
vuldb·2026-05-19·CVSS 7.1
CVE-2026-32882 [HIGH] strukturag libheif up to 1.21.x libheif/pixelimage.cc HeifPixelImage::overlay out-of-bounds
A vulnerability described as critical has been identified in strukturag libheif up to 1.21.x. The impacted element is the function HeifPixelImage::overlay of the file libheif/pixelimage.cc. Such manipulation leads to out-of-bounds read.
This vulnerability is uniquely identified as CVE-2026-32882. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is recommended.
No detection rules found.
No public exploits indexed.
https://github.com/strukturag/libheif/releases/tag/v1.22.0https://github.com/strukturag/libheif/security/advisories/GHSA-hg7q-rjr2-8x46https://access.redhat.com/security/cve/CVE-2026-32882https://bugzilla.redhat.com/show_bug.cgi?id=2480000https://github.com/strukturag/libheif/security/advisories/GHSA-hg7q-rjr2-8x46https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32882.json
2026-05-19
Published