Out-of-bounds write in libheif - CVE-2026-62291

 

Out-of-bounds write in libheif - CVE-2026-62291

Published: June 26, 2026 / Updated: August 19, 2026


Vulnerability identifier: #VU135517
CSH Severity: Medium
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-62291
CWE-ID: CWE-787
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause memory corruption.

The vulnerability exists due to out-of-bounds write in unc_encoder_component_interleave::encode_tile when re-encoding a decoded image with mismatched primary and auxiliary alpha plane dimensions. A remote attacker can trick the victim into opening a specially crafted HEIF sequence file and re-encoding the decoded frame to cause memory corruption.

User interaction is required to open a crafted file, and exploitation occurs through a decode and re-encode workflow using the public APIs.


Affected software

libheif
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
Fedora
Desktop Applications Module
SUSE Package Hub 15
Ubuntu
libheif (Ubuntu package)
libheif1-debuginfo
libheif-ffmpeg
gdk-pixbuf-loader-libheif
libheif-devel
libheif-ffmpeg-debuginfo
gdk-pixbuf-loader-libheif-debuginfo
libheif-dav1d-debuginfo
libheif1
libheif-aom
libheif-jpeg
libheif-jpeg-debuginfo
libheif-aom-debuginfo
libheif-rav1e
libheif-dav1d
libheif-rav1e-debuginfo
libheif-debugsource
libheif
aom

How to mitigate CVE-2026-62291

Install security update from vendor's website.

libheif - update to 1.23.1
libheif (Ubuntu package) - addressed in versions 1.1.0-2ubuntu0.1~esm4, 1.6.1-1ubuntu0.1~esm4, 1.12.0-2ubuntu0.1~esm4, 1.17.6-1ubuntu4.8
libheif1-debuginfo - update to 1.23.1-150700.3.18.1
libheif-ffmpeg - update to 1.23.1-150700.3.18.1
gdk-pixbuf-loader-libheif - update to 1.23.1-150700.3.18.1
libheif-devel - update to 1.23.1-150700.3.18.1
libheif-ffmpeg-debuginfo - update to 1.23.1-150700.3.18.1
gdk-pixbuf-loader-libheif-debuginfo - update to 1.23.1-150700.3.18.1
libheif-dav1d-debuginfo - update to 1.23.1-150700.3.18.1
libheif1 - update to 1.23.1-150700.3.18.1
libheif-aom - update to 1.23.1-150700.3.18.1
libheif-jpeg - update to 1.23.1-150700.3.18.1
libheif-jpeg-debuginfo - update to 1.23.1-150700.3.18.1
libheif-aom-debuginfo - update to 1.23.1-150700.3.18.1
libheif-rav1e - update to 1.23.1-150700.3.18.1
libheif-dav1d - update to 1.23.1-150700.3.18.1
libheif-rav1e-debuginfo - update to 1.23.1-150700.3.18.1
libheif-debugsource - update to 1.23.1-150700.3.18.1
libheif - addressed in versions 1.23.5-3.el10_3, 1.23.5-3.el10_4
aom - addressed in versions 3.13.3-1.el10_3, 3.13.3-1.el10_4

External References

Related Security Bulletins