CVE-2026-49271
published 2026-06-19CVE-2026-49271: libheif is a HEIF and AVIF file format decoder and encoder. Prior to version 1.22.1, the uncompressed HEIF decoder validates explicit icef compressed-unit…
PriorityP432medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
EPSS
0.20%
9.9th percentile
libheif is a HEIF and AVIF file format decoder and encoder. Prior to version 1.22.1, the uncompressed HEIF decoder validates explicit icef compressed-unit offsets using unit_offset + unit_size. Because the addition can wrap, a crafted HEIF file can pass the range check and then construct a vector from iterators outside the compressed item buffer, producing an out-of-bounds heap read and crash. Version 1.22.1 patches the issue.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| struktur | libheif | < 1.22.1 | 1.22.1 |
| strukturag | libheif | < 1.22.1 | 1.22.1 |
| ubuntu | libheif | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
vendor_redhat6.5MEDIUM
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
libheif vulnerabilities
vendor_ubuntu·2026-06-29·CVSS 6.5
CVE-2026-47178 [MEDIUM] libheif vulnerabilities
Title: libheif vulnerabilities
Summary: Several security issues were fixed in libheif.
It was discovered that libheif incorrectly handled certain crafted HEIF
files. An attacker could possibly use this issue to cause a denial of
service or execute arbitrary code. (CVE-2026-47178)
It was discovered that libheif incorrectly validated offsets when
decoding certain crafted HEIF files. An attacker could possibly use this
issue to cause a denial of service. This issue only affected Ubuntu 26.04
LTS. (CVE-2026-49271)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
libheif: libheif: Denial of Service via crafted HEIF file due to integer wrap-around
vendor_redhat·2026-06-19·CVSS 6.5
CVE-2026-49271 [MEDIUM] CWE-190 libheif: libheif: Denial of Service via crafted HEIF file due to integer wrap-around
libheif: libheif: Denial of Service via crafted HEIF file due to integer wrap-around
libheif is a HEIF and AVIF file format decoder and encoder. Prior to version 1.22.1, the uncompressed HEIF decoder validates explicit icef compressed-unit offsets using unit_offset + unit_size. Because the addition can wrap, a crafted HEIF file can pass the range check and then construct a vector from iterators outside the compressed item buffer, producing an out-of-bounds heap read and crash. Version 1.22.1 patches the issue.
A flaw was found in libheif, a decoder and encoder for HEIF and AVIF file formats. A remote attacker could exploit this vulnerability by providing a specially crafted HEIF file. The uncompressed HEIF decoder's validation of `icef` compressed-unit offsets can experience an integer w
VulDB
strukturag libheif up to 1.22.0 HEIF Decoder out-of-bounds (GHSA-r7qj-cg5r-r6vf)
vuldb·2026-06-19
CVE-2026-49271 [LOW] strukturag libheif up to 1.22.0 HEIF Decoder out-of-bounds (GHSA-r7qj-cg5r-r6vf)
A vulnerability has been found in strukturag libheif up to 1.22.0 and classified as problematic. Affected is an unknown function of the component HEIF Decoder. Performing a manipulation results in out-of-bounds read.
This vulnerability is cataloged as CVE-2026-49271. It is possible to initiate the attack remotely. There is no exploit available.
The affected component should be upgraded.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-49271 libheif: libheif: Denial of Service via crafted HEIF file due to integer wrap-around [fedora-all]
bugzilla·2026-06-30·CVSS 6.5
CVE-2026-49271 [MEDIUM] CVE-2026-49271 libheif: libheif: Denial of Service via crafted HEIF file due to integer wrap-around [fedora-all]
CVE-2026-49271 libheif: libheif: Denial of Service via crafted HEIF file due to integer wrap-around [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
libheif is a HEIF and AVIF file format decoder and encoder. Prior to version 1.22.1, the uncompressed HEIF decoder validates explicit icef compressed-unit offsets using unit_offset + unit_size. Because the addition can wrap, a crafted HEIF file can pass the range check and then construct a vector from iterators outside the compressed item buffer, producing an out-of-bounds heap read and crash. Version 1.22.1 patches the issue.
Bugzilla
CVE-2026-49271 libheif: libheif: Denial of Service via crafted HEIF file due to integer wrap-around [epel-all]
bugzilla·2026-06-30·CVSS 6.5
CVE-2026-49271 [MEDIUM] CVE-2026-49271 libheif: libheif: Denial of Service via crafted HEIF file due to integer wrap-around [epel-all]
CVE-2026-49271 libheif: libheif: Denial of Service via crafted HEIF file due to integer wrap-around [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
libheif is a HEIF and AVIF file format decoder and encoder. Prior to version 1.22.1, the uncompressed HEIF decoder validates explicit icef compressed-unit offsets using unit_offset + unit_size. Because the addition can wrap, a crafted HEIF file can pass the range check and then construct a vector from iterators outside the compressed item buffer, producing an out-of-bounds heap read and crash. Version 1.22.1 patches the issue.
Bugzilla
CVE-2026-49271 libheif: libheif: Denial of Service via crafted HEIF file due to integer wrap-around
bugzilla·2026-06-19·CVSS 6.5
CVE-2026-49271 [MEDIUM] CVE-2026-49271 libheif: libheif: Denial of Service via crafted HEIF file due to integer wrap-around
CVE-2026-49271 libheif: libheif: Denial of Service via crafted HEIF file due to integer wrap-around
libheif is a HEIF and AVIF file format decoder and encoder. Prior to version 1.22.1, the uncompressed HEIF decoder validates explicit icef compressed-unit offsets using unit_offset + unit_size. Because the addition can wrap, a crafted HEIF file can pass the range check and then construct a vector from iterators outside the compressed item buffer, producing an out-of-bounds heap read and crash. Version 1.22.1 patches the issue.
2026-06-19
Published