Out-of-bounds read in libheif - CVE-2026-47251
Published: May 20, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service and disclose sensitive information.
The vulnerability exists due to out-of-bounds read in vvdec_push_data2 in libheif's VVC decoder plugin when parsing a crafted HEIF file with a VVC track. A remote attacker can supply a specially crafted HEIF file to cause a denial of service and disclose sensitive information.
User interaction is required to open or decode the crafted file. Only builds with VVC support enabled are vulnerable.
Affected software
Fedora
libheif
aom
How to mitigate CVE-2026-47251
libheif - addressed in versions 1.23.5-3.el10_3, 1.23.5-3.el10_4
aom - addressed in versions 3.13.3-1.el10_3, 3.13.3-1.el10_4