Heap OOB Read Vulnerability in libheif Affects ImageDecoding
CVE-2026-48029
7.1HIGH
What is CVE-2026-48029?
The libheif library, used for decoding and encoding HEIF and AVIF file formats, has been found to contain a heap out-of-bounds read vulnerability. This issue arises in versions 1.19.0 through 1.21.2, specifically within the ImageItem_Grid::decode_grid_tile function due to tile-coordinate underflow when using the irot decoding technique. Version 1.22.0 addresses the vulnerability, mitigating potential risks associated with image processing.
Affected Version(s)
libheif >= 1.19.0, < 1.22.0
