← Back

Libheif

libheif

Vendor: Struktur • 21 CVEs

CVEs (21)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Struktur
1Libheif
May 27, 2026
May 22, 2026
5.1 MEDIUM· v4
8.1 HIGH· v3
N/A· v2
libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, a crafted HEIF sequence file where the saiz box declares more samples than actually exist in the track's chunk table causes a heap...Show more
libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, a crafted HEIF sequence file where the saiz box declares more samples than actually exist in the track's chunk table causes a heap-buffer-overflow (out-of-bounds read) in the SampleAuxInfoReader constructor. The SampleAuxInfoReader constructor iterates over saiz->get_num_samples() samples but doesn't validate that this count is consistent with the number of chunks in the chunks vector. When saiz declares more samples than the chunks cover, the loop increments current_chunk past chunks.size(), causing an out-of-bounds read on the chunks vector. The vulnerability is triggered during file parsing (heif_context_read_from_file) without any additional user interaction. Any application using libheif to open untrusted HEIF files is affected. This issue has been fixed in version 1.22.0.Show less
1Struktur
1Libheif
May 27, 2026
May 22, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, a malformed HEIF sequence file can trigger an out-of-bounds read in core sequence parsing logic, causing DoS. A malformed file can...Show more
libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, a malformed HEIF sequence file can trigger an out-of-bounds read in core sequence parsing logic, causing DoS. A malformed file can have stco.entry_count == 0 (creating no chunks) while still passing validation because saio.entry_count == 0 matches, but with saiz.sample_count > 0 the SampleAuxInfoReader constructor still enters its loop. This leads to an out-of-bounds dereference on the empty chunks[0] in chunked mode.Show less
1Struktur
1Libheif
May 21, 2026
May 19, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and prior contain a heap-buffer-overflow (write) vulnerability in the grid tile compositing, allowing an attacker to write 64 bytes of fully att...Show more
libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and prior contain a heap-buffer-overflow (write) vulnerability in the grid tile compositing, allowing an attacker to write 64 bytes of fully attacker-controlled data past the end of a chroma plane heap allocation by crafting a HEIF/AVIF file with a 1×4 grid of odd-height tiles. The overflow is triggered during normal image decoding with default build configuration. The written bytes are chroma (Cb/Cr) pixel values from the attacking tile, giving the attacker full control over the overflow content. This issue has been fixed in version 1.22.0.Show less
1Struktur
1Libheif
May 20, 2026
May 19, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and below, a crafted 800-byte HEIF sequence file causes an infinite loop in Box_stts::get_sample_duration(), consuming 100% CPU indefinitely...Show more
libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and below, a crafted 800-byte HEIF sequence file causes an infinite loop in Box_stts::get_sample_duration(), consuming 100% CPU indefinitely with zero progress, leading to DoS. The loop has no iteration limit or timeout and is triggered during file open (parsing) - before any user interaction or image decoding. The process stays alive (no crash, no error logged), making it invisible to crash-based monitoring. This issue has been fixed in version 1.22.0.Show less
1Struktur
1Libheif
May 20, 2026
May 19, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and below, a crafted 792-byte HEIF sequence file with samples_per_chunk=0 in the stsc box causes an unsigned integer underflow in the Chunk c...Show more
libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and below, a crafted 792-byte HEIF sequence file with samples_per_chunk=0 in the stsc box causes an unsigned integer underflow in the Chunk constructor (m_last_sample = 0 + 0 - 1 = UINT32_MAX), mapping all samples to an empty chunk and resulting in a denial of service. When any sample is accessed, the library reads from index 0 of an empty std::vector, causing a guaranteed SEGV (null-page read). The file parses successfully without producing an error; the crash occurs on the first frame access. This issue has been fixed in version 1.22.0.Show less
1Struktur
1Libheif
Feb 25, 2026
Dec 29, 2025
N/A· v4
7.1 HIGH· v3
N/A· v2
libheif is an HEIF and AVIF file format decoder and encoder. Prior to version 1.21.0, a crafted HEIF that exercises the overlay image item path triggers a heap buffer over-read in `HeifPixelImage::overlay()`. The functio...Show more
libheif is an HEIF and AVIF file format decoder and encoder. Prior to version 1.21.0, a crafted HEIF that exercises the overlay image item path triggers a heap buffer over-read in `HeifPixelImage::overlay()`. The function computes a negative row length (likely from an unclipped overlay rectangle or invalid offsets), which then underflows when converted to `size_t` and is passed to `memcpy`, causing a very large read past the end of the source plane and a crash. Version 1.21.0 contains a patch. As a workaround, avoid decoding images using `iovl` overlay boxes.Show less
1Struktur
1Libheif
May 8, 2025
Apr 21, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
libheif before 1.19.6 has a NULL pointer dereference in ImageItem_Grid::get_decoder in image-items/grid.cc because a grid image can reference a nonexistent image item.
1Struktur
1Libheif
May 8, 2025
Apr 21, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
libheif before 1.19.6 has a NULL pointer dereference in ImageItem_iden in image-items/iden.cc.
1Struktur
1Libheif
Apr 15, 2025
Apr 7, 2025
N/A· v4
6.2 MEDIUM· v3
N/A· v2
Buffer Overflow vulnerability in libheif 1.19.7 allows a local attacker to execute arbitrary code via the SAO (Sample Adaptive Offset) processing of libde265.
2Debian
Struktur
2Debian Linux
Libheif
Mar 24, 2025
Oct 15, 2024
N/A· v4
8.1 HIGH· v3
N/A· v2
In Libheif 1.17.6, insufficient checks in ImageOverlay::parse() decoding a heif file containing an overlay image with forged offsets can lead to an out-of-bounds read and write.
1Struktur
1Libheif
Mar 24, 2025
Mar 5, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
libheif <= 1.17.6 contains a memory leak in the function JpegEncoder::Encode. This flaw allows an attacker to cause a denial of service attack.
1Struktur
1Libheif
Nov 21, 2024
Dec 7, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
libheif v1.17.5 was discovered to contain a segmentation violation via the function UncompressedImageCodec::get_luma_bits_per_pixel_from_configuration_unci.
1Struktur
1Libheif
Nov 21, 2024
Dec 7, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
libheif v1.17.5 was discovered to contain a segmentation violation via the function find_exif_tag at /libheif/exif.cc.
1Struktur
1Libheif
Nov 21, 2024
Dec 7, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
libheif v1.17.5 was discovered to contain a segmentation violation via the component /libheif/exif.cc.
1Struktur
1Libheif
Nov 21, 2024
Dec 7, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
libheif v1.17.5 was discovered to contain a segmentation violation via the function UncompressedImageCodec::decode_uncompressed_image.
2Fedoraproject
Struktur
2Fedora
Libheif
Jan 29, 2025
May 5, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
A Segmentation fault caused by a floating point exception exists in libheif 1.15.1 using crafted heif images via the heif::Fraction::round() function in box.cc, which causes a denial of service.
1Struktur
1Libheif
Mar 11, 2025
Feb 24, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
There is a vulnerability in the strided image data parsing code in the emscripten wrapper for libheif. An attacker could exploit this through a crafted image file to cause a buffer overflow in linear memory during a mem...Show more
There is a vulnerability in the strided image data parsing code in the emscripten wrapper for libheif. An attacker could exploit this through a crafted image file to cause a buffer overflow in linear memory during a memcpy call. Show less
1Struktur
1Libheif
Nov 21, 2024
Nov 3, 2021
N/A· v4
8.1 HIGH· v3
5.8 MEDIUM· v2
Buffer overflow vulnerability in function convert_colorspace in heif_colorconversion.cc in libheif v1.6.2, allows attackers to cause a denial of service and disclose sensitive information, via a crafted HEIF file.
1Struktur
1Libheif
Nov 21, 2024
Jul 21, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in heif::Box_iref::get_references in libheif 1.4.0, allows attackers to cause a Denial of Service or possibly other unspecified impact due to an invalid memory read.
1Struktur
1Libheif
Nov 21, 2024
Jul 21, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Floating point exception in function Fraction in libheif 1.4.0, allows attackers to cause a Denial of Service or possibly other unspecified impacts.