Out-of-bounds read in libheif - CVE-2026-48029
Published: May 20, 2026 / Updated: July 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service and disclose sensitive information.
The vulnerability exists due to out-of-bounds read in ImageItem_Grid::decode_grid_tile when parsing a crafted HEIF/HEIC file containing a grid-derived item with an irot rotation property. A remote attacker can send a specially crafted file to cause a denial of service and disclose sensitive information.
User interaction is required to open or decode the crafted file.
Affected software
Debian Linux
Ubuntu
libheif (Debian package)
libheif (Ubuntu package)
How to mitigate CVE-2026-48029
libheif (Debian package) - update to 1.19.8-1+deb13u1
libheif (Ubuntu package) - addressed in versions 1.20.2-1ubuntu0.6, 1.21.2-3ubuntu0.3