Medium severity5.5NVD Advisory· Published Jul 21, 2026· Updated Jul 27, 2026
CVE-2026-47709
CVE-2026-47709
Description
libheif is a HEIF and AVIF file format decoder and encoder. Versions prior to 1.22.0 crashes in the public C API heif_image_handle_get_image_tiling() when a malformed uncompressed HEIF image item has an associated uncC property but no associated ispe property. In debug builds this trips the ispe && uncC assertion in ImageItem_uncompressed::get_heif_image_tiling(). In a release/NDEBUG ASan build, the same file causes a null pointer read at address 0xa8. Version 1.22.0 fixes the issue.
Affected products
4cpe:2.3:a:struktur:libheif:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:struktur:libheif:*:*:*:*:*:*:*:*range: <1.22.0
- (no CPE)range: <1.22.0
- osv-coords2 versionspkg:rpm/opensuse/libheif&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/libheif&distro=openSUSE%20Tumbleweed
< 1.23.0-160000.1.1+ 1 more
- (no CPE)range: < 1.23.0-160000.1.1
- (no CPE)range: < 1.22.2-1.1
Patches
Vulnerability mechanics
References
3- github.com/strukturag/libheif/issues/1802nvdExploitIssue TrackingThird Party Advisory
- github.com/strukturag/libheif/pull/1806nvdExploitIssue TrackingPatchThird Party Advisory
- github.com/strukturag/libheif/security/advisories/GHSA-4h72-vqgp-9376nvdExploitVendor AdvisoryMitigation
News mentions
0No linked articles in our index yet.