Unrated severityOSV Advisory· Published Dec 29, 2025· Updated Dec 30, 2025
libheif has Potential Heap Buffer Over-Read
CVE-2025-68431
Description
libheif is an HEIF and AVIF file format decoder and encoder. Prior to version 1.21.0, a crafted HEIF that exercises the overlay image item path triggers a heap buffer over-read in HeifPixelImage::overlay(). The function computes a negative row length (likely from an unclipped overlay rectangle or invalid offsets), which then underflows when converted to size_t and is passed to memcpy, causing a very large read past the end of the source plane and a crash. Version 1.21.0 contains a patch. As a workaround, avoid decoding images using iovl overlay boxes.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
9v1.1.0, v1.10.0, v1.11.0, …+ 1 more
- (no CPE)range: v1.1.0, v1.10.0, v1.11.0, …
- (no CPE)range: <1.21.0
- osv-coords7 versionspkg:rpm/opensuse/libheif&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/libheif&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/libheif&distro=openSUSE%20Tumbleweedpkg:rpm/suse/libheif&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP7pkg:rpm/suse/libheif&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP7pkg:rpm/suse/libheif&distro=SUSE%20Linux%20Enterprise%20Server%2016.0pkg:rpm/suse/libheif&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20applications%2016.0
< 1.12.0-150400.3.17.1+ 6 more
- (no CPE)range: < 1.12.0-150400.3.17.1
- (no CPE)range: < 1.19.7-160000.3.1
- (no CPE)range: < 1.21.1-1.1
- (no CPE)range: < 1.19.5-150700.3.3.1
- (no CPE)range: < 1.19.5-150700.3.3.1
- (no CPE)range: < 1.19.7-160000.3.1
- (no CPE)range: < 1.19.7-160000.3.1
Patches
Vulnerability mechanics
References
3- github.com/strukturag/libheif/commit/b8c12a7b70f46c9516711a988483bed377b78d46mitrex_refsource_MISC
- github.com/strukturag/libheif/releases/tag/v1.21.0mitrex_refsource_MISC
- github.com/strukturag/libheif/security/advisories/GHSA-j87x-4gmq-cqfqmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.