Use of uninitialized resource in libheif - CVE-2026-32814

 

Use of uninitialized resource in libheif - CVE-2026-32814

Published: May 20, 2026


Vulnerability identifier: #VU131976
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-32814
CWE-ID: CWE-908
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to use of uninitialized resource in ImageItem_Grid::decode_and_paste_tile_image() in libheif/image-items/grid.cc when decoding a crafted HEIF or AVIF grid image with strict_decoding=false. A remote attacker can supply a specially crafted file with a corrupted tile to disclose sensitive information.

User interaction is required to process the crafted file, and the issue occurs with the default decoding behavior where tile decode failures are returned as success.


Affected software

libheif
openSUSE Leap
libheif-devel
libheif-debugsource
gdk-pixbuf-loader-libheif-debuginfo
libheif1-debuginfo
gdk-pixbuf-loader-libheif
libheif1
libheif1-32bit-debuginfo
libheif1-32bit
libheif1-64bit-debuginfo
libheif1-64bit

How to mitigate CVE-2026-32814

Install security update from vendor's website.

libheif - update to 1.22.0
libheif-devel - update to 1.12.0-150400.3.20.1
libheif-debugsource - update to 1.12.0-150400.3.20.1
gdk-pixbuf-loader-libheif-debuginfo - update to 1.12.0-150400.3.20.1
libheif1-debuginfo - update to 1.12.0-150400.3.20.1
gdk-pixbuf-loader-libheif - update to 1.12.0-150400.3.20.1
libheif1 - update to 1.12.0-150400.3.20.1
libheif1-32bit-debuginfo - update to 1.12.0-150400.3.20.1
libheif1-32bit - update to 1.12.0-150400.3.20.1
libheif1-64bit-debuginfo - update to 1.12.0-150400.3.20.1
libheif1-64bit - update to 1.12.0-150400.3.20.1

External References

Related Security Bulletins