Out-of-bounds read in libheif - CVE-2026-47251

 

Out-of-bounds read in libheif - CVE-2026-47251

Published: May 20, 2026


Vulnerability identifier: #VU131962
CSH Severity: Medium
CVSS v4: 7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-47251
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service and disclose sensitive information.

The vulnerability exists due to out-of-bounds read in vvdec_push_data2 in libheif's VVC decoder plugin when parsing a crafted HEIF file with a VVC track. A remote attacker can supply a specially crafted HEIF file to cause a denial of service and disclose sensitive information.

User interaction is required to open or decode the crafted file. Only builds with VVC support enabled are vulnerable.


Affected software

libheif

How to mitigate CVE-2026-47251

Install security update from vendor's website.

libheif - update to 1.22.0

External References

Related Security Bulletins