CVE-2026-48029
7.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H
Exploitability: 2.8 / Impact: 4.2
Source: security-advisories@github.com (Secondary)
Description
libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.19.0 through 1.21.2 have a heap OOB read in ImageItem_Grid::decode_grid_tile via irot-induced tile-coordinate underflow. Version 1.22.0 fixes the issue.
Affected (1)
Related CWEs
CWE-125
Out-of-bounds Read
The product reads data past the end, or before the beginning, of the intended buffer.
CWE-191
Integer Underflow (Wrap or Wraparound)
The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.
References (3)
Source: security-advisories@github.com
Patch
Source: security-advisories@github.com
MitigationVendor AdvisoryExploit
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
MitigationVendor AdvisoryExploit
Timeline
No history available yet.