High severity7.1NVD Advisory· Published Jul 22, 2026· Updated Aug 6, 2026
CVE-2026-48029
CVE-2026-48029
Description
libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.19.0 through 1.21.2 have a heap OOB read in ImageItem_Grid::decode_grid_tile via irot-induced tile-coordinate underflow. Version 1.22.0 fixes the issue.
Affected products
4cpe:2.3:a:struktur:libheif:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:struktur:libheif:*:*:*:*:*:*:*:*range: >=1.19.0,<1.22.0
- (no CPE)range: 1.19.0 - 1.21.2
- osv-coords2 versionspkg:rpm/opensuse/libheif&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/libheif&distro=openSUSE%20Tumbleweed
< 1.23.0-160000.1.1+ 1 more
- (no CPE)range: < 1.23.0-160000.1.1
- (no CPE)range: < 1.22.2-1.1
Patches
Vulnerability mechanics
References
2- github.com/strukturag/libheif/commit/e523ec0bf379110b7c33d4c159f8b1202d332157nvdPatch
- github.com/strukturag/libheif/security/advisories/GHSA-6x5f-qchq-cxqvnvdMitigationVendor AdvisoryExploit
News mentions
0No linked articles in our index yet.