Количество 10
Количество 10
CVE-2025-68431
libheif is an HEIF and AVIF file format decoder and encoder. Prior to version 1.21.0, a crafted HEIF that exercises the overlay image item path triggers a heap buffer over-read in `HeifPixelImage::overlay()`. The function computes a negative row length (likely from an unclipped overlay rectangle or invalid offsets), which then underflows when converted to `size_t` and is passed to `memcpy`, causing a very large read past the end of the source plane and a crash. Version 1.21.0 contains a patch. As a workaround, avoid decoding images using `iovl` overlay boxes.
CVE-2025-68431
libheif is an HEIF and AVIF file format decoder and encoder. Prior to version 1.21.0, a crafted HEIF that exercises the overlay image item path triggers a heap buffer over-read in `HeifPixelImage::overlay()`. The function computes a negative row length (likely from an unclipped overlay rectangle or invalid offsets), which then underflows when converted to `size_t` and is passed to `memcpy`, causing a very large read past the end of the source plane and a crash. Version 1.21.0 contains a patch. As a workaround, avoid decoding images using `iovl` overlay boxes.
CVE-2025-68431
libheif is an HEIF and AVIF file format decoder and encoder. Prior to ...
openSUSE-SU-2026:20076-1
Security update for libheif
SUSE-SU-2026:0377-1
Security update for libheif
SUSE-SU-2026:0087-1
Security update for libheif
ROS-20260622-73-0024
Уязвимость libheif
BDU:2026-09348
Уязвимость функции HeifPixelImage::overlay() библиотеки libheif, позволяющая нарушителю вызвать отказ в обслуживании
openSUSE-SU-2026:20974-1
Security update for libheif
SUSE-SU-2026:2622-1
Security update for libheif
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2025-68431 libheif is an HEIF and AVIF file format decoder and encoder. Prior to version 1.21.0, a crafted HEIF that exercises the overlay image item path triggers a heap buffer over-read in `HeifPixelImage::overlay()`. The function computes a negative row length (likely from an unclipped overlay rectangle or invalid offsets), which then underflows when converted to `size_t` and is passed to `memcpy`, causing a very large read past the end of the source plane and a crash. Version 1.21.0 contains a patch. As a workaround, avoid decoding images using `iovl` overlay boxes. | CVSS3: 6.5 | 0% Низкий | 7 месяцев назад | |
CVE-2025-68431 libheif is an HEIF and AVIF file format decoder and encoder. Prior to version 1.21.0, a crafted HEIF that exercises the overlay image item path triggers a heap buffer over-read in `HeifPixelImage::overlay()`. The function computes a negative row length (likely from an unclipped overlay rectangle or invalid offsets), which then underflows when converted to `size_t` and is passed to `memcpy`, causing a very large read past the end of the source plane and a crash. Version 1.21.0 contains a patch. As a workaround, avoid decoding images using `iovl` overlay boxes. | CVSS3: 6.5 | 0% Низкий | 7 месяцев назад | |
CVE-2025-68431 libheif is an HEIF and AVIF file format decoder and encoder. Prior to ... | CVSS3: 6.5 | 0% Низкий | 7 месяцев назад | |
openSUSE-SU-2026:20076-1 Security update for libheif | 0% Низкий | 6 месяцев назад | ||
SUSE-SU-2026:0377-1 Security update for libheif | 0% Низкий | 6 месяцев назад | ||
SUSE-SU-2026:0087-1 Security update for libheif | 0% Низкий | 7 месяцев назад | ||
ROS-20260622-73-0024 Уязвимость libheif | CVSS3: 7.1 | 0% Низкий | около 1 месяца назад | |
BDU:2026-09348 Уязвимость функции HeifPixelImage::overlay() библиотеки libheif, позволяющая нарушителю вызвать отказ в обслуживании | CVSS3: 6.5 | 0% Низкий | 7 месяцев назад | |
openSUSE-SU-2026:20974-1 Security update for libheif | около 2 месяцев назад | |||
SUSE-SU-2026:2622-1 Security update for libheif | около 1 месяца назад |
Уязвимостей на страницу