Out-of-bounds read in libheif - CVE-2026-62292
Published: June 26, 2026 / Updated: August 19, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to out-of-bounds read in unc_decoder::get_compressed_image_data_uncompressed() when decoding an advertised image tile from a crafted HEIF uncompressed image through heif_image_handle_decode_image_tile(). A remote attacker can supply a specially crafted HEIF file and trigger tile decoding to cause a denial of service.
The issue is not triggered by merely opening the file; the vulnerable path is reached when an application enumerates tiling metadata and decodes an advertised tile.
Affected software
Debian Linux
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
Fedora
Desktop Applications Module
SUSE Package Hub 15
Ubuntu
libheif (Ubuntu package)
libheif (Debian package)
libheif-debugsource
libheif-ffmpeg
gdk-pixbuf-loader-libheif
libheif-devel
libheif-ffmpeg-debuginfo
gdk-pixbuf-loader-libheif-debuginfo
libheif-dav1d-debuginfo
libheif1
libheif-aom
libheif-jpeg
libheif-jpeg-debuginfo
libheif-aom-debuginfo
libheif-rav1e
libheif-dav1d
libheif-rav1e-debuginfo
libheif1-debuginfo
libheif
aom
How to mitigate CVE-2026-62292
libheif (Ubuntu package) - addressed in versions 1.17.6-1ubuntu4.7, 1.21.2-3ubuntu0.4
libheif (Debian package) - update to 1.19.8-1+deb13u1
libheif-debugsource - update to 1.23.1-150700.3.18.1
libheif-ffmpeg - update to 1.23.1-150700.3.18.1
gdk-pixbuf-loader-libheif - update to 1.23.1-150700.3.18.1
libheif-devel - update to 1.23.1-150700.3.18.1
libheif-ffmpeg-debuginfo - update to 1.23.1-150700.3.18.1
gdk-pixbuf-loader-libheif-debuginfo - update to 1.23.1-150700.3.18.1
libheif-dav1d-debuginfo - update to 1.23.1-150700.3.18.1
libheif1 - update to 1.23.1-150700.3.18.1
libheif-aom - update to 1.23.1-150700.3.18.1
libheif-jpeg - update to 1.23.1-150700.3.18.1
libheif-jpeg-debuginfo - update to 1.23.1-150700.3.18.1
libheif-aom-debuginfo - update to 1.23.1-150700.3.18.1
libheif-rav1e - update to 1.23.1-150700.3.18.1
libheif-dav1d - update to 1.23.1-150700.3.18.1
libheif-rav1e-debuginfo - update to 1.23.1-150700.3.18.1
libheif1-debuginfo - update to 1.23.1-150700.3.18.1
libheif - addressed in versions 1.23.5-3.el10_3, 1.23.5-3.el10_4
aom - addressed in versions 3.13.3-1.el10_3, 3.13.3-1.el10_4