Количество 9
Количество 9
BDU:2026-12022
Уязвимость функции HeifPixelImage::copy_image_to() файла libheif/pixelimage.cc декодера и кодировщика форматов файлов libheif, позволяющая нарушителю выполнить произвольный код
CVE-2026-32740
libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and prior contain a heap-buffer-overflow (write) vulnerability in the grid tile compositing, allowing an attacker to write 64 bytes of fully attacker-controlled data past the end of a chroma plane heap allocation by crafting a HEIF/AVIF file with a 1×4 grid of odd-height tiles. The overflow is triggered during normal image decoding with default build configuration. The written bytes are chroma (Cb/Cr) pixel values from the attacking tile, giving the attacker full control over the overflow content. This issue has been fixed in version 1.22.0.
CVE-2026-32740
libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and prior contain a heap-buffer-overflow (write) vulnerability in the grid tile compositing, allowing an attacker to write 64 bytes of fully attacker-controlled data past the end of a chroma plane heap allocation by crafting a HEIF/AVIF file with a 1×4 grid of odd-height tiles. The overflow is triggered during normal image decoding with default build configuration. The written bytes are chroma (Cb/Cr) pixel values from the attacking tile, giving the attacker full control over the overflow content. This issue has been fixed in version 1.22.0.
CVE-2026-32740
libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and prior contain a heap-buffer-overflow (write) vulnerability in the grid tile compositing, allowing an attacker to write 64 bytes of fully attacker-controlled data past the end of a chroma plane heap allocation by crafting a HEIF/AVIF file with a 1×4 grid of odd-height tiles. The overflow is triggered during normal image decoding with default build configuration. The written bytes are chroma (Cb/Cr) pixel values from the attacking tile, giving the attacker full control over the overflow content. This issue has been fixed in version 1.22.0.
CVE-2026-32740
libheif is a HEIF and AVIF file format decoder and encoder. Versions 1 ...
ROS-20260729-80-0023
Уязвимость libheif
ROS-20260729-73-0016
Уязвимость libheif
openSUSE-SU-2026:20974-1
Security update for libheif
SUSE-SU-2026:2622-1
Security update for libheif
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
BDU:2026-12022 Уязвимость функции HeifPixelImage::copy_image_to() файла libheif/pixelimage.cc декодера и кодировщика форматов файлов libheif, позволяющая нарушителю выполнить произвольный код | CVSS3: 8.8 | 1% Низкий | 4 месяца назад | |
CVE-2026-32740 libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and prior contain a heap-buffer-overflow (write) vulnerability in the grid tile compositing, allowing an attacker to write 64 bytes of fully attacker-controlled data past the end of a chroma plane heap allocation by crafting a HEIF/AVIF file with a 1×4 grid of odd-height tiles. The overflow is triggered during normal image decoding with default build configuration. The written bytes are chroma (Cb/Cr) pixel values from the attacking tile, giving the attacker full control over the overflow content. This issue has been fixed in version 1.22.0. | CVSS3: 8.8 | 1% Низкий | 4 месяца назад | |
CVE-2026-32740 libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and prior contain a heap-buffer-overflow (write) vulnerability in the grid tile compositing, allowing an attacker to write 64 bytes of fully attacker-controlled data past the end of a chroma plane heap allocation by crafting a HEIF/AVIF file with a 1×4 grid of odd-height tiles. The overflow is triggered during normal image decoding with default build configuration. The written bytes are chroma (Cb/Cr) pixel values from the attacking tile, giving the attacker full control over the overflow content. This issue has been fixed in version 1.22.0. | CVSS3: 8.8 | 1% Низкий | 4 месяца назад | |
CVE-2026-32740 libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and prior contain a heap-buffer-overflow (write) vulnerability in the grid tile compositing, allowing an attacker to write 64 bytes of fully attacker-controlled data past the end of a chroma plane heap allocation by crafting a HEIF/AVIF file with a 1×4 grid of odd-height tiles. The overflow is triggered during normal image decoding with default build configuration. The written bytes are chroma (Cb/Cr) pixel values from the attacking tile, giving the attacker full control over the overflow content. This issue has been fixed in version 1.22.0. | CVSS3: 8.8 | 1% Низкий | 4 месяца назад | |
CVE-2026-32740 libheif is a HEIF and AVIF file format decoder and encoder. Versions 1 ... | CVSS3: 8.8 | 1% Низкий | 4 месяца назад | |
ROS-20260729-80-0023 Уязвимость libheif | CVSS3: 8.8 | 1% Низкий | около 2 месяцев назад | |
ROS-20260729-73-0016 Уязвимость libheif | CVSS3: 8.8 | 1% Низкий | около 2 месяцев назад | |
openSUSE-SU-2026:20974-1 Security update for libheif | 3 месяца назад | |||
SUSE-SU-2026:2622-1 Security update for libheif | 3 месяца назад |
Уязвимостей на страницу