Out-of-bounds read in libheif - CVE-2026-62292

 

Out-of-bounds read in libheif - CVE-2026-62292

Published: June 26, 2026 / Updated: August 19, 2026


Vulnerability identifier: #VU135516
CSH Severity: Medium
CVSS v4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-62292
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to out-of-bounds read in unc_decoder::get_compressed_image_data_uncompressed() when decoding an advertised image tile from a crafted HEIF uncompressed image through heif_image_handle_decode_image_tile(). A remote attacker can supply a specially crafted HEIF file and trigger tile decoding to cause a denial of service.

The issue is not triggered by merely opening the file; the vulnerable path is reached when an application enumerates tiling metadata and decodes an advertised tile.


Affected software

libheif
Debian Linux
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
Fedora
Desktop Applications Module
SUSE Package Hub 15
Ubuntu
libheif (Ubuntu package)
libheif (Debian package)
libheif-debugsource
libheif-ffmpeg
gdk-pixbuf-loader-libheif
libheif-devel
libheif-ffmpeg-debuginfo
gdk-pixbuf-loader-libheif-debuginfo
libheif-dav1d-debuginfo
libheif1
libheif-aom
libheif-jpeg
libheif-jpeg-debuginfo
libheif-aom-debuginfo
libheif-rav1e
libheif-dav1d
libheif-rav1e-debuginfo
libheif1-debuginfo
libheif
aom

How to mitigate CVE-2026-62292

Install security update from vendor's website.

libheif - update to 1.23.1
libheif (Ubuntu package) - addressed in versions 1.17.6-1ubuntu4.7, 1.21.2-3ubuntu0.4
libheif (Debian package) - update to 1.19.8-1+deb13u1
libheif-debugsource - update to 1.23.1-150700.3.18.1
libheif-ffmpeg - update to 1.23.1-150700.3.18.1
gdk-pixbuf-loader-libheif - update to 1.23.1-150700.3.18.1
libheif-devel - update to 1.23.1-150700.3.18.1
libheif-ffmpeg-debuginfo - update to 1.23.1-150700.3.18.1
gdk-pixbuf-loader-libheif-debuginfo - update to 1.23.1-150700.3.18.1
libheif-dav1d-debuginfo - update to 1.23.1-150700.3.18.1
libheif1 - update to 1.23.1-150700.3.18.1
libheif-aom - update to 1.23.1-150700.3.18.1
libheif-jpeg - update to 1.23.1-150700.3.18.1
libheif-jpeg-debuginfo - update to 1.23.1-150700.3.18.1
libheif-aom-debuginfo - update to 1.23.1-150700.3.18.1
libheif-rav1e - update to 1.23.1-150700.3.18.1
libheif-dav1d - update to 1.23.1-150700.3.18.1
libheif-rav1e-debuginfo - update to 1.23.1-150700.3.18.1
libheif1-debuginfo - update to 1.23.1-150700.3.18.1
libheif - addressed in versions 1.23.5-3.el10_3, 1.23.5-3.el10_4
aom - addressed in versions 3.13.3-1.el10_3, 3.13.3-1.el10_4

External References

Related Security Bulletins