Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-41069

Опубликовано: 22 мая 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 6.5

Описание

libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, a malformed HEIF sequence file can trigger an out-of-bounds read in core sequence parsing logic, causing DoS. A malformed file can have stco.entry_count == 0 (creating no chunks) while still passing validation because saio.entry_count == 0 matches, but with saiz.sample_count > 0 the SampleAuxInfoReader constructor still enters its loop. This leads to an out-of-bounds dereference on the empty chunks[0] in chunked mode.

РелизСтатусПримечание
devel

needs-triage

esm-apps/bionic

not-affected

code not present
esm-apps/focal

not-affected

code not present
esm-apps/jammy

not-affected

code not present
jammy

not-affected

code not present
noble

not-affected

code not present
questing

released

1.20.2-1ubuntu0.4
resolute

released

1.21.2-3ubuntu0.1
upstream

not-affected

1.22.0

Показывать по

EPSS

Процентиль: 17%
0.00253
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
nvd
3 месяца назад

libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, a malformed HEIF sequence file can trigger an out-of-bounds read in core sequence parsing logic, causing DoS. A malformed file can have stco.entry_count == 0 (creating no chunks) while still passing validation because saio.entry_count == 0 matches, but with saiz.sample_count > 0 the SampleAuxInfoReader constructor still enters its loop. This leads to an out-of-bounds dereference on the empty chunks[0] in chunked mode.

CVSS3: 6.5
debian
3 месяца назад

libheif is a HEIF and AVIF file format decoder and encoder. In version ...

suse-cvrf
2 месяца назад

Security update for libheif

suse-cvrf
около 2 месяцев назад

Security update for libheif

EPSS

Процентиль: 17%
0.00253
Низкий

6.5 Medium

CVSS3