Heap Corruption in libheif's Image Decoding and Encoding
CVE-2026-62291

5.3MEDIUM

Key Information:

Vendor

Strukturag

Status
Vendor
CVE Published:
18 August 2026

What is CVE-2026-62291?

A vulnerability in libheif prior to version 1.23.1 allows for heap corruption when decoding crafted image sequences. This occurs due to a failure in dimension validation between the primary and auxiliary planes during the decode and re-encode process. The improper handling of alpha plane dimensions can lead to out-of-bounds writes and reads, which may allow attackers to manipulate memory, potentially compromising the application's stability and security. Updating to version 1.23.1 resolves this critical issue, ensuring proper dimension checks are enforced.

Affected Version(s)

libheif < 1.23.1

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.