CVE-2026-3950
published 2026-03-11CVE-2026-3950: A vulnerability was identified in strukturag libheif up to 1.21.2. This impacts the function Track::load of the file libheif/sequences/track.cc of the…
PriorityP411low3.3CVSS 3.1
AVLACLPRLUINSUCNINAL
EPSS
0.12%
2.0th percentile
A vulnerability was identified in strukturag libheif up to 1.21.2. This impacts the function Track::load of the file libheif/sequences/track.cc of the component stsz/stts. The manipulation leads to out-of-bounds read. The attack needs to be performed locally. The exploit is publicly available and might be used. Applying a patch is the recommended action to fix this issue. The patch available is inofficial and not approved yet.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libheif | — | — |
| strukturag | libheif | — | — |
| strukturag | libheif | — | — |
| strukturag | libheif | — | — |
| ubuntu | libheif | — | — |
CVSS provenance
nvdv3.13.3LOWCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
nvdv4.01.9LOWCVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.01.7LOWAV:L/AC:L/Au:S/C:N/I:N/A:P
osv4.8MEDIUM
vendor_ubuntu6.5MEDIUM
vendor_debian4.8LOW
vendor_redhat4.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
libheif vulnerabilities
vendor_ubuntu·2026-06-18·CVSS 6.5
CVE-2026-32740 [MEDIUM] libheif vulnerabilities
Title: libheif vulnerabilities
Summary: Several security issues were fixed in libheif.
Elhanan Haenel discovered that libheif incorrectly handled certain
malformed HEIF sequence files. An attacker could possibly use this
issue to cause a denial of service. This issue only affected Ubuntu 25.10
and Ubuntu 26.04 LTS. (CVE-2026-32738)
Elhanan Haenel discovered that libheif incorrectly handled certain
malformed HEIF sequence files, leading to an infinite loop. An attacker
could possibly use this issue to cause libheif to use excessive
resources, resulting in a denial of service. This issue only affected
Ubuntu 25.10 and Ubuntu 26.04 LTS. (CVE-2026-32739)
Elhanan Haenel discovered that libheif incorrectly handled certain
crafted HEIF/AVIF image files. An attacker could possibly use this iss
Red Hat
libheif: libheif: Denial of Service via out-of-bounds read in Track::load function
vendor_redhat·2026-03-11·CVSS 4.8
CVE-2026-3950 [MEDIUM] CWE-125 libheif: libheif: Denial of Service via out-of-bounds read in Track::load function
libheif: libheif: Denial of Service via out-of-bounds read in Track::load function
A vulnerability was identified in strukturag libheif up to 1.21.2. This impacts the function Track::load of the file libheif/sequences/track.cc of the component stsz/stts. The manipulation leads to out-of-bounds read. The attack needs to be performed locally. The exploit is publicly available and might be used. Applying a patch is the recommended action to fix this issue. The patch available is inofficial and not approved yet.
A flaw was found in libheif. A local attacker could exploit an out-of-bounds read vulnerability in the `Track::load` function within the `stsz/stts` component. This manipulation could lead to a Denial of Service (DoS), making the affected system or application unavailable.
Package:
Debian
CVE-2026-3950: libheif - A vulnerability was identified in strukturag libheif up to 1.21.2. This impacts ...
vendor_debian·2026·CVSS 4.8
CVE-2026-3950 [MEDIUM] CVE-2026-3950: libheif - A vulnerability was identified in strukturag libheif up to 1.21.2. This impacts ...
A vulnerability was identified in strukturag libheif up to 1.21.2. This impacts the function Track::load of the file libheif/sequences/track.cc of the component stsz/stts. The manipulation leads to out-of-bounds read. The attack needs to be performed locally. The exploit is publicly available and might be used. Applying a patch is the recommended action to fix this issue. The patch available is inofficial and not approved yet.
Scope: local
bookworm: resolved
bullseye: resolved
forky: open
sid: open
trixie: resolved
GHSA
GHSA-cp66-x46c-28rg: A vulnerability was identified in strukturag libheif up to 1
ghsa_unreviewed·2026-03-11
CVE-2026-3950 [MEDIUM] CWE-119 GHSA-cp66-x46c-28rg: A vulnerability was identified in strukturag libheif up to 1
A vulnerability was identified in strukturag libheif up to 1.21.2. This impacts the function Track::load of the file libheif/sequences/track.cc of the component stsz/stts. The manipulation leads to out-of-bounds read. The attack needs to be performed locally. The exploit is publicly available and might be used. Applying a patch is the recommended action to fix this issue. The patch available is inofficial and not approved yet.
OSV
CVE-2026-3950: A vulnerability was identified in strukturag libheif up to 1
osv·2026-03-11·CVSS 4.8
CVE-2026-3950 [MEDIUM] CVE-2026-3950: A vulnerability was identified in strukturag libheif up to 1
A vulnerability was identified in strukturag libheif up to 1.21.2. This impacts the function Track::load of the file libheif/sequences/track.cc of the component stsz/stts. The manipulation leads to out-of-bounds read. The attack needs to be performed locally. The exploit is publicly available and might be used. Applying a patch is the recommended action to fix this issue. The patch available is inofficial and not approved yet.
No detection rules found.
No public exploits indexed.
https://github.com/Niebelungen-D/pocs/tree/main/heif_dec_sequence_chunk_idx_oobhttps://github.com/strukturag/libheif/https://github.com/strukturag/libheif/issues/1715https://github.com/strukturag/libheif/pull/1721https://vuldb.com/?ctiid.350382https://vuldb.com/?id.350382https://vuldb.com/?submit.766431
2026-03-11
Published