SB2026081953 - Debian update for libheif
Published: August 19, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 12 vulnerabilities.
1) Out-of-bounds read (CVE-ID: CVE-2025-68431)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to potentially sensitive information or crash the application.
The vulnerability exists due to a boundary condition within the HeifPixelImage::overlay() function. A remote attacker can create a specially crafted file, trick the victim into opening it, trigger an out-of-bounds read error and read contents of memory on the system or perform a denial of service attack.
2) Out-of-bounds write (CVE-ID: CVE-2026-32740)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to out-of-bounds write in HeifPixelImage::copy_image_to() when decoding a crafted grid-based HEIF or AVIF image. A remote attacker can supply a specially crafted file to execute arbitrary code.
User interaction is required to open or decode a crafted file. Exploitation requires grid images using YCbCr 4:2:0 chroma subsampling with odd-height tiles.
3) Heap-based buffer overflow (CVE-ID: CVE-2026-32741)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service and potentially execute arbitrary code.
The vulnerability exists due to heap-based buffer overflow in MaskImageCodec::decode_mask_image() in libheif/image-items/mask_image.cc when parsing a crafted HEIF file containing a mask image. A remote attacker can supply a specially crafted HEIF file with an oversized iloc extent to cause a denial of service and potentially execute arbitrary code.
User interaction is required to open or process the crafted HEIF file. Exploitation requires an mski item with mskC bits_per_pixel set to 8 and image properties that enter the single-memcpy branch where stride equals width.
4) Out-of-bounds read (CVE-ID: CVE-2026-32882)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service or disclose sensitive information.
The vulnerability exists due to out-of-bounds read in HeifPixelImage::overlay() when parsing a crafted HEIF file containing an overlay image whose child image uses a different alpha-channel bit depth than the color channels. A remote attacker can supply a specially crafted HEIF file to cause a denial of service or disclose sensitive information.
User interaction is required to open or otherwise process the crafted file.
5) Out-of-bounds write (CVE-ID: CVE-2026-47178)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to out-of-bounds write in unc_decoder_component_interleave::decode_tile() when parsing a crafted HEIF file using the uncompressed unci codec with tiled, component-interleaved 4:2:0 content. A remote attacker can supply a specially crafted HEIF file to execute arbitrary code.
Only instances built with WITH_UNCOMPRESSED_CODEC=ON are vulnerable.
6) Use of uninitialized resource (CVE-ID: CVE-2026-47247)
CWE-ID: CWE-908 - Use of Uninitialized Resource
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to use of uninitialized resource and incorrect calculation in libheif grid image decoding when parsing a crafted AVIF or HEIC grid image. A remote attacker can upload a specially crafted image for decoding and obtain heap memory contents from visible pixels in the decoded output to disclose sensitive information.
The leaked data may include heap contents such as library function pointers that can be used to defeat ASLR, and the issue is exposed when decoded output is made available to the attacker.
7) NULL pointer dereference (CVE-ID: CVE-2026-47709)
CWE-ID: CWE-476 - NULL Pointer Dereference
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a null pointer dereference in heif_image_handle_get_image_tiling() when processing a malformed uncompressed HEIF image item missing the ispe property. A remote attacker can supply a specially crafted HEIF file to cause a denial of service.
The issue is reachable through the public C API and may trigger an assertion in debug builds.
8) Integer overflow (CVE-ID: CVE-2026-47714)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service and disclose sensitive information.
The vulnerability exists due to integer overflow or wraparound in the inline mask parsing code in libheif/region.cc when parsing a crafted HEIF file. A remote attacker can trick the victim into opening a crafted file to cause a denial of service and disclose sensitive information.
The issue is reachable when applications raise the max_image_size_pixels limit or disable it via LIBHEIF_SECURITY_LIMITS=off.
9) Out-of-bounds read (CVE-ID: CVE-2026-48029)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service and disclose sensitive information.
The vulnerability exists due to out-of-bounds read in ImageItem_Grid::decode_grid_tile when parsing a crafted HEIF/HEIC file containing a grid-derived item with an irot rotation property. A remote attacker can send a specially crafted file to cause a denial of service and disclose sensitive information.
User interaction is required to open or decode the crafted file.
10) Out-of-bounds read (CVE-ID: CVE-2026-49271)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in unc_decoder::get_compressed_image_data_uncompressed when parsing a crafted HEIF file with wrapped icef compressed-unit offsets and sizes. A remote attacker can supply a specially crafted HEIF file to cause a denial of service.
The issue is reached when the cmpC compressed unit type is not image_tile, and user interaction is required to decode the crafted media.
11) Integer underflow (CVE-ID: CVE-2026-62289)
CWE-ID: CWE-191 - Integer underflow
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to integer underflow in the Fraction constructor when processing a crafted HEIF/AVIF file through the tiling API with process_image_transformations=1. A remote attacker can supply a specially crafted file to cause a denial of service.
User interaction is required to open the crafted file, or the issue can be triggered server-side when uploaded content is processed automatically.
12) Out-of-bounds read (CVE-ID: CVE-2026-62292)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to out-of-bounds read in unc_decoder::get_compressed_image_data_uncompressed() when decoding an advertised image tile from a crafted HEIF uncompressed image through heif_image_handle_decode_image_tile(). A remote attacker can supply a specially crafted HEIF file and trigger tile decoding to cause a denial of service.
The issue is not triggered by merely opening the file; the vulnerable path is reached when an application enumerates tiling metadata and decodes an advertised tile.
Remediation
Install update from vendor's website.