Last updated 19 June 2026
Last updated 19 August 2026
libheif is a HEIF and AVIF file format decoder and encoder. Prior to version 1.22.0, two bugs in libheif chain to leak process heap memory as visible pixel values in decoded grid images. An attacker who uploads a crafted AVIF/HEIC file to any server-side image processor (WordPress, Sharp/libvips, ImageMagick, etc.) can recover heap data - including library function pointers sufficient to defeat ASLR, or any other secret - from the publicly-downloadable transcoded JPEG/PNG/WebP output. Local attack vectors are also possible. Version 1.22.0 fixes the issue.
libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.1 and earlier, crafted grid, iovl, and iden reference graphs can repeatedly decode the same base image because processedids is copied per branch and ImageItem::decodeimage() has no shared operation budget. This vulnerability is fixed in 1.23.2.
Last updated 19 June 2026
Last updated 19 June 2026
Last updated 19 June 2026
Last updated 19 June 2026
Last updated 19 June 2026
Last updated 19 June 2026
Last updated 29 June 2026
libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.3, the no-icef full-item branch of uncdecoder::getcompressedimagedatauncompressed() in libheif/codecs/uncompressed/uncdecoder.cc retains an addition-based range check that can wrap when a crafted uncompressed tile grid produces a large rangestartoffset and rangesize. The overflow makes the bounds comparison pass and allows heifimagehandledecodeimagetile() to call memcpy() with an invalid source pointer and a very large length when decoding a valid high-index advertised tile. This incomplete remediation of CVE-2026-62292 can reliably crash tile-processing applications, while whole-image decoding is not claimed to reach the demonstrated path. This issue is fixed in version 1.23.3.
Last updated 19 June 2026
Last updated 18 September 2026
Last updated 27 August 2026
libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1.23.2, the public heifregionitemaddregioninlinemaskdata() function in libheif/api/libheif/heifregions.cc accepts maskdatalen without verifying that it equals the byte count required by width and height. A later heifregiongetmaskimage() call derives the read length from the region geometry, so an undersized stored buffer causes heifregiongetinlinemaskimage() to read beyond the heap allocation and copy adjacent bytes into the returned monochrome mask image. This can disclose heap data or crash an application that constructs region metadata through the writer API, while the file-parsing path is not affected because it validates the canonical mask size. This issue is fixed in version 1.23.2.