Out-of-bounds read in libheif - CVE-2026-32882

 

Out-of-bounds read in libheif - CVE-2026-32882

Published: May 20, 2026


Vulnerability identifier: #VU131973
CSH Severity: Medium
CVSS v4: 7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-32882
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service or disclose sensitive information.

The vulnerability exists due to out-of-bounds read in HeifPixelImage::overlay() when parsing a crafted HEIF file containing an overlay image whose child image uses a different alpha-channel bit depth than the color channels. A remote attacker can supply a specially crafted HEIF file to cause a denial of service or disclose sensitive information.

User interaction is required to open or otherwise process the crafted file.


Affected software

libheif
Debian Linux
Discourse
libheif (Debian package)

How to mitigate CVE-2026-32882

Install security update from vendor's website.

libheif - update to 1.22.0
Discourse - addressed in versions 2026.1.6, 2026.5.2, 2026.6.1, 2026.7.0
libheif (Debian package) - update to 1.19.8-1+deb13u1

External References

Related Security Bulletins