CVE-2026-41069
published 2026-05-22CVE-2026-41069: libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, a malformed HEIF sequence file can trigger an out-of-bounds read in…
PriorityP431medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
EPSS
0.25%
16.7th percentile
libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, a malformed HEIF sequence file can trigger an out-of-bounds read in core sequence parsing logic, causing DoS. A malformed file can have stco.entry_count == 0 (creating no chunks) while still passing validation because saio.entry_count == 0 matches, but with saiz.sample_count > 0 the SampleAuxInfoReader constructor still enters its loop. This leads to an out-of-bounds dereference on the empty chunks[0] in chunked mode.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| struktur | libheif | < 1.22.0 | 1.22.0 |
| strukturag | libheif | < 1.22.0 | 1.22.0 |
| ubuntu | libheif | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
cvelistv5v3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
libheif vulnerabilities
vendor_ubuntu·2026-06-18·CVSS 6.5
CVE-2026-32740 [MEDIUM] libheif vulnerabilities
Title: libheif vulnerabilities
Summary: Several security issues were fixed in libheif.
Elhanan Haenel discovered that libheif incorrectly handled certain
malformed HEIF sequence files. An attacker could possibly use this
issue to cause a denial of service. This issue only affected Ubuntu 25.10
and Ubuntu 26.04 LTS. (CVE-2026-32738)
Elhanan Haenel discovered that libheif incorrectly handled certain
malformed HEIF sequence files, leading to an infinite loop. An attacker
could possibly use this issue to cause libheif to use excessive
resources, resulting in a denial of service. This issue only affected
Ubuntu 25.10 and Ubuntu 26.04 LTS. (CVE-2026-32739)
Elhanan Haenel discovered that libheif incorrectly handled certain
crafted HEIF/AVIF image files. An attacker could possibly use this iss
VulDB
strukturag libheif up to 1.21.x AVIF File entry_count out-of-bounds (GHSA-p82x-fpmv-576r)
vuldb·2026-05-23
CVE-2026-41069 [LOW] strukturag libheif up to 1.21.x AVIF File entry_count out-of-bounds (GHSA-p82x-fpmv-576r)
A vulnerability categorized as problematic has been discovered in strukturag libheif up to 1.21.x. Impacted is an unknown function of the component AVIF File Handler. Such manipulation of the argument entry_count leads to out-of-bounds read.
This vulnerability is uniquely identified as CVE-2026-41069. The attack can be launched remotely. No exploit exists.
It is advisable to upgrade the affected component.
CVEList
libheif allows Out-of-bounds vector access leading to invalid dereference (DoS)
cvelistv5·2026-05-22·CVSS 6.5
CVE-2026-41069 [MEDIUM] CWE-125 libheif allows Out-of-bounds vector access leading to invalid dereference (DoS)
libheif allows Out-of-bounds vector access leading to invalid dereference (DoS)
libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, a malformed HEIF sequence file can trigger an out-of-bounds read in core sequence parsing logic, causing DoS. A malformed file can have stco.entry_count == 0 (creating no chunks) while still passing validation because saio.entry_count == 0 matches, but with saiz.sample_count > 0 the SampleAuxInfoReader constructor still enters its loop. This leads to an out-of-bounds dereference on the empty chunks[0] in chunked mode.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-41069 libheif: libheif: Denial of Service via malformed HEIF sequence file [epel-all]
bugzilla·2026-06-16·CVSS 6.5
CVE-2026-41069 [MEDIUM] CVE-2026-41069 libheif: libheif: Denial of Service via malformed HEIF sequence file [epel-all]
CVE-2026-41069 libheif: libheif: Denial of Service via malformed HEIF sequence file [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-41069 libheif: libheif: Denial of Service via malformed HEIF sequence file [fedora-all]
bugzilla·2026-06-16·CVSS 6.5
CVE-2026-41069 [MEDIUM] CVE-2026-41069 libheif: libheif: Denial of Service via malformed HEIF sequence file [fedora-all]
CVE-2026-41069 libheif: libheif: Denial of Service via malformed HEIF sequence file [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-41069 libheif: libheif: Denial of Service via malformed HEIF sequence file
bugzilla·2026-05-22·CVSS 6.5
CVE-2026-41069 [MEDIUM] CVE-2026-41069 libheif: libheif: Denial of Service via malformed HEIF sequence file
CVE-2026-41069 libheif: libheif: Denial of Service via malformed HEIF sequence file
libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, a malformed HEIF sequence file can trigger an out-of-bounds read in core sequence parsing logic, causing DoS. A malformed file can have stco.entry_count == 0 (creating no chunks) while still passing validation because saio.entry_count == 0 matches, but with saiz.sample_count > 0 the SampleAuxInfoReader constructor still enters its loop. This leads to an out-of-bounds dereference on the empty chunks[0] in chunked mode.
2026-05-22
Published