CVE-2026-47178: libheif has Heap Out Of Bounds Write in unci subsystem
Last updated 29 June 2026
Other sources
libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.19.0 through 1.21.2, a crafted HEIF file (uncompressed unci codec, tiled, component-interleaved, 4:2:0) triggers a heap out-of-bounds write in libheif's uncompressed tile decoder. The write overwrites the C++ vtable pointer of an adjacent uncdecodercomponentinterleave object; the next virtual call dispatches to an attacker-chosen address. Version 1.22.0 patches the issue.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
libheifto a version that resolves this vulnerability.Fixed in 1.22.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-47178?
CVE-2026-47178 is classified with a risk score of 26.
What software is affected by CVE-2026-47178?
The vulnerability CVE-2026-47178 affects Debian's libheif package.
How do I fix CVE-2026-47178?
To fix CVE-2026-47178, update your Debian libheif package to the latest version.
What are the potential impacts of CVE-2026-47178?
CVE-2026-47178 could lead to security breaches that compromise system integrity and stability.
When was CVE-2026-47178 last updated?
CVE-2026-47178 was last updated on 29 June 2026.