Integer underflow in libheif - CVE-2026-62289

 

Integer underflow in libheif - CVE-2026-62289

Published: June 26, 2026 / Updated: August 19, 2026


Vulnerability identifier: #VU135515
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-62289
CWE-ID: CWE-191
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to integer underflow in the Fraction constructor when processing a crafted HEIF/AVIF file through the tiling API with process_image_transformations=1. A remote attacker can supply a specially crafted file to cause a denial of service.

User interaction is required to open the crafted file, or the issue can be triggered server-side when uploaded content is processed automatically.


Affected software

libheif
Debian Linux
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
Fedora
Desktop Applications Module
SUSE Package Hub 15
openSUSE Leap
Ubuntu
libheif (Ubuntu package)
libheif1-64bit
libheif1-64bit-debuginfo
libheif1-32bit
libheif1-32bit-debuginfo
gdk-pixbuf-loader-libheif
libheif-devel
libheif1-debuginfo
libheif-debugsource
libheif1
gdk-pixbuf-loader-libheif-debuginfo
libheif (Debian package)
libheif-rav1e-debuginfo
libheif-dav1d
libheif-rav1e
libheif-aom-debuginfo
libheif-jpeg-debuginfo
libheif-jpeg
libheif-aom
libheif-dav1d-debuginfo
libheif-ffmpeg-debuginfo
libheif-ffmpeg
libheif
aom

How to mitigate CVE-2026-62289

Install security update from vendor's website.

libheif - update to 1.23.1
libheif (Ubuntu package) - addressed in versions 1.1.0-2ubuntu0.1~esm4, 1.6.1-1ubuntu0.1~esm4, 1.12.0-2ubuntu0.1~esm4, 1.17.6-1ubuntu4.7, 1.17.6-1ubuntu4.8, 1.21.2-3ubuntu0.4
libheif1-64bit - update to 1.12.0-150400.3.23.2
libheif1-64bit-debuginfo - update to 1.12.0-150400.3.23.2
libheif1-32bit - update to 1.12.0-150400.3.23.2
libheif1-32bit-debuginfo - update to 1.12.0-150400.3.23.2
gdk-pixbuf-loader-libheif - addressed in versions 1.12.0-150400.3.23.2, 1.23.1-150700.3.18.1
libheif-devel - addressed in versions 1.12.0-150400.3.23.2, 1.23.1-150700.3.18.1
libheif1-debuginfo - addressed in versions 1.12.0-150400.3.23.2, 1.23.1-150700.3.18.1
libheif-debugsource - addressed in versions 1.12.0-150400.3.23.2, 1.23.1-150700.3.18.1
libheif1 - addressed in versions 1.12.0-150400.3.23.2, 1.23.1-150700.3.18.1
gdk-pixbuf-loader-libheif-debuginfo - addressed in versions 1.12.0-150400.3.23.2, 1.23.1-150700.3.18.1
libheif (Debian package) - update to 1.19.8-1+deb13u1
libheif-rav1e-debuginfo - update to 1.23.1-150700.3.18.1
libheif-dav1d - update to 1.23.1-150700.3.18.1
libheif-rav1e - update to 1.23.1-150700.3.18.1
libheif-aom-debuginfo - update to 1.23.1-150700.3.18.1
libheif-jpeg-debuginfo - update to 1.23.1-150700.3.18.1
libheif-jpeg - update to 1.23.1-150700.3.18.1
libheif-aom - update to 1.23.1-150700.3.18.1
libheif-dav1d-debuginfo - update to 1.23.1-150700.3.18.1
libheif-ffmpeg-debuginfo - update to 1.23.1-150700.3.18.1
libheif-ffmpeg - update to 1.23.1-150700.3.18.1
libheif - addressed in versions 1.23.5-3.el10_3, 1.23.5-3.el10_4
aom - addressed in versions 3.13.3-1.el10_3, 3.13.3-1.el10_4

External References

Related Security Bulletins