Out-of-bounds read in libheif - CVE-2026-32882
Published: May 20, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service or disclose sensitive information.
The vulnerability exists due to out-of-bounds read in HeifPixelImage::overlay() when parsing a crafted HEIF file containing an overlay image whose child image uses a different alpha-channel bit depth than the color channels. A remote attacker can supply a specially crafted HEIF file to cause a denial of service or disclose sensitive information.
User interaction is required to open or otherwise process the crafted file.
Affected software
Debian Linux
Discourse
libheif (Debian package)
How to mitigate CVE-2026-32882
Discourse - addressed in versions 2026.1.6, 2026.5.2, 2026.6.1, 2026.7.0
libheif (Debian package) - update to 1.19.8-1+deb13u1