High severity8.8OSV Advisory· Published Apr 23, 2019· Updated Jun 17, 2026
CVE-2019-11471
CVE-2019-11471
Description
libheif 1.4.0 has a use-after-free in heif::HeifContext::Image::set_alpha_channel in heif_context.h because heif_context.cc mishandles references to non-existing alpha images.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3v1.1.0, v1.2.0, v1.3.0, …+ 2 more
- (no CPE)range: v1.1.0, v1.2.0, v1.3.0, …
- cpe:2.3:a:struktur:libheif:1.4.0:*:*:*:*:*:*:*
- (no CPE)range: <1.4.0
Patches
Vulnerability mechanics
References
2- github.com/strukturag/libheif/commit/995a4283d8ed2d0d2c1ceb1a577b993df2f0e014nvdPatchThird Party Advisory
- github.com/strukturag/libheif/issues/123nvdExploitPatchThird Party Advisory
News mentions
0No linked articles in our index yet.