PT-2026-42473 · Unknown+1 · Gdk-Pixbuf-Loader-Libheif+1

CVE-2026-48029

·

Published

2026-05-21

·

Updated

2026-08-06

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H
Name of the Vulnerable Software and Affected Versions libheif versions 1.19.0 through 1.21.2
Description libheif, a HEIF and AVIF file format decoder and encoder, contains a heap out-of-bounds (OOB) read. This occurs in the ImageItem Grid::decode grid tile() function due to a tile-coordinate underflow induced by the irot box. This issue can lead to application crashes, such as segmentation faults, when processing specific HEIC grid images, particularly portrait photos from certain mobile devices.
Recommendations Update libheif to version 1.22.0.

Exploit

Fix

Integer Underflow

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-48029
ECHO-F301-3BAE-8FC2
GHSA-6X5F-QCHQ-CXQV
OPENSUSE-SU-2026:10878-1
OPENSUSE-SU-2026:20974-1
SUSE-SU-2026:22153-1
SUSE-SU-2026:2622-1
USN-8526-1

Affected Products

Ubuntu
Gdk-Pixbuf-Loader-Libheif