CVE-2026-47178
published 2026-07-21CVE-2026-47178: libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.19.0 through 1.21.2, a crafted HEIF file (uncompressed `unci` codec, tiled…
PriorityP343high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.20%
10.0th percentile
libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.19.0 through 1.21.2, a crafted HEIF file (uncompressed `unci` codec, tiled, component-interleaved, 4:2:0) triggers a heap out-of-bounds write in libheif's uncompressed tile decoder. The write overwrites the C++ vtable pointer of an adjacent `unc_decoder_component_interleave` object; the next virtual call dispatches to an attacker-chosen address. Version 1.22.0 patches the issue.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| struktur | libheif | >= 1.19.0 < 1.22.0 | 1.22.0 |
| strukturag | libheif | — | — |
| ubuntu | libheif | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-47178 libheif: libheif: Arbitrary code execution via crafted HEIF file [epel-all]
bugzilla·2026-07-23·CVSS 6.1
CVE-2026-47178 [MEDIUM] CVE-2026-47178 libheif: libheif: Arbitrary code execution via crafted HEIF file [epel-all]
CVE-2026-47178 libheif: libheif: Arbitrary code execution via crafted HEIF file [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.19.0 through 1.21.2, a crafted HEIF file (uncompressed `unci` codec, tiled, component-interleaved, 4:2:0) triggers a heap out-of-bounds write in libheif's uncompressed tile decoder. The write overwrites the C++ vtable pointer of an adjacent `unc_decoder_component_interleave` object; the next virtual call dispatches to an attacker-chosen address. Version 1.22.0 patches the issue.
Bugzilla
CVE-2026-47178 libheif: libheif: Arbitrary code execution via crafted HEIF file [fedora-all]
bugzilla·2026-07-23·CVSS 6.1
CVE-2026-47178 [MEDIUM] CVE-2026-47178 libheif: libheif: Arbitrary code execution via crafted HEIF file [fedora-all]
CVE-2026-47178 libheif: libheif: Arbitrary code execution via crafted HEIF file [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.19.0 through 1.21.2, a crafted HEIF file (uncompressed `unci` codec, tiled, component-interleaved, 4:2:0) triggers a heap out-of-bounds write in libheif's uncompressed tile decoder. The write overwrites the C++ vtable pointer of an adjacent `unc_decoder_component_interleave` object; the next virtual call dispatches to an attacker-chosen address. Version 1.22.0 patches the issue.
Bugzilla
CVE-2026-47178 libheif: libheif: Arbitrary code execution via crafted HEIF file
bugzilla·2026-07-21·CVSS 6.1
CVE-2026-47178 [MEDIUM] CVE-2026-47178 libheif: libheif: Arbitrary code execution via crafted HEIF file
CVE-2026-47178 libheif: libheif: Arbitrary code execution via crafted HEIF file
libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.19.0 through 1.21.2, a crafted HEIF file (uncompressed `unci` codec, tiled, component-interleaved, 4:2:0) triggers a heap out-of-bounds write in libheif's uncompressed tile decoder. The write overwrites the C++ vtable pointer of an adjacent `unc_decoder_component_interleave` object; the next virtual call dispatches to an attacker-chosen address. Version 1.22.0 patches the issue.
2026-07-21
Published