Out-of-Bounds Read in HEIF File Parser Affects strukturag Product
CVE-2026-3949
Key Information:
- Vendor
Strukturag
- Status
- Vendor
- CVE Published:
- 11 March 2026
Badges
What is CVE-2026-3949?
A vulnerability exists within strukturag's HEIF File Parser, specifically in the vvdec_push_data2 function of decoder_vvdec.cc. By manipulating the argument size, it is possible to trigger an out-of-bounds read, which may lead to information disclosure or other security risks. This vulnerability must be exploited locally, necessitating access to the affected system. The issue has been publicly disclosed, and a corresponding patch is available for implementation to mitigate the risk.
Affected Version(s)
libheif 1.21.0
libheif 1.21.1
libheif 1.21.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
