Out-of-bounds write in libheif - CVE-2026-32740
Published: May 20, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to out-of-bounds write in HeifPixelImage::copy_image_to() when decoding a crafted grid-based HEIF or AVIF image. A remote attacker can supply a specially crafted file to execute arbitrary code.
User interaction is required to open or decode a crafted file. Exploitation requires grid images using YCbCr 4:2:0 chroma subsampling with odd-height tiles.
Affected software
Debian Linux
libheif (Debian package)
How to mitigate CVE-2026-32740
libheif (Debian package) - update to 1.19.8-1+deb13u1