CVE-2026-48029
published 2026-07-22CVE-2026-48029: libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.19.0 through 1.21.2 have a heap OOB read in ImageItem_Grid::decode_grid_tile via…
PriorityP334high7.1CVSS 3.1
AVNACLPRNUIRSUCLINAH
EPSS
0.27%
18.7th percentile
libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.19.0 through 1.21.2 have a heap OOB read in ImageItem_Grid::decode_grid_tile via irot-induced tile-coordinate underflow. Version 1.22.0 fixes the issue.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| strukturag | libheif | — | — |
| ubuntu | libheif | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
libheif vulnerabilities
vendor_ubuntu·2026-07-09
CVE-2026-47709 libheif vulnerabilities
Title: libheif vulnerabilities
Summary: Several security issues were fixed in libheif.
Xianrui Dong discovered that libheif had an out-of-bounds read in its
HEIF sequence track parser. An attacker could possibly use this issue
to cause a denial of service or obtain sensitive information. This issue
only affected Ubuntu 26.04 LTS. (CVE-2026-47254)
Junyi Liu discovered that libheif had a null pointer dereference in its
image tiling interface. An attacker could possibly use this issue to
cause a denial of service. (CVE-2026-47709)
Calvin Young and Enoch Chow discovered that libheif had an integer
overflow in its inline mask size calculation. An attacker could
possibly use this issue to cause a denial of service or obtain sensitive
information. (CVE-2026-47714)
Ariel Koren discovered that
VulDB
strukturag libheif up to 1.21.2 ImageItem_Grid::decode_grid_tile heap-based overflow
vuldb·2026-07-22·CVSS 7.1
CVE-2026-48029 [HIGH] strukturag libheif up to 1.21.2 ImageItem_Grid::decode_grid_tile heap-based overflow
A vulnerability described as critical has been identified in strukturag libheif up to 1.21.2. The affected element is an unknown function of the component ImageItem_Grid::decode_grid_tile. Executing a manipulation can lead to heap-based buffer overflow.
This vulnerability is handled as CVE-2026-48029. The attack can be executed remotely. There is not any exploit available.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-48029 libheif: libheif: Denial of Service via crafted image file processing [fedora-all]
bugzilla·2026-07-23·CVSS 7.1
CVE-2026-48029 [HIGH] CVE-2026-48029 libheif: libheif: Denial of Service via crafted image file processing [fedora-all]
CVE-2026-48029 libheif: libheif: Denial of Service via crafted image file processing [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.19.0 through 1.21.2 have a heap OOB read in ImageItem_Grid::decode_grid_tile via irot-induced tile-coordinate underflow. Version 1.22.0 fixes the issue.
Bugzilla
CVE-2026-48029 libheif: libheif: Denial of Service via crafted image file processing [epel-all]
bugzilla·2026-07-23·CVSS 7.1
CVE-2026-48029 [HIGH] CVE-2026-48029 libheif: libheif: Denial of Service via crafted image file processing [epel-all]
CVE-2026-48029 libheif: libheif: Denial of Service via crafted image file processing [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.19.0 through 1.21.2 have a heap OOB read in ImageItem_Grid::decode_grid_tile via irot-induced tile-coordinate underflow. Version 1.22.0 fixes the issue.
Bugzilla
CVE-2026-48029 libheif: libheif: Denial of Service via crafted image file processing
bugzilla·2026-07-22·CVSS 7.1
CVE-2026-48029 [HIGH] CVE-2026-48029 libheif: libheif: Denial of Service via crafted image file processing
CVE-2026-48029 libheif: libheif: Denial of Service via crafted image file processing
libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.19.0 through 1.21.2 have a heap OOB read in ImageItem_Grid::decode_grid_tile via irot-induced tile-coordinate underflow. Version 1.22.0 fixes the issue.
2026-07-22
Published