PT-2026-42834 · Libheif+2 · Libheif+2

·

CVE-2026-41071

·

Published

2026-04-13

·

Updated

2026-08-25

CVSS v2.0

9.4

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:C
Name of the Vulnerable Software and Affected Versions libheif versions prior to 1.22.0
Description A heap-buffer-overflow (out-of-bounds read) occurs in the SampleAuxInfoReader constructor when parsing a crafted HEIF sequence file. The issue arises because the constructor iterates over the number of samples declared in the saiz box using saiz->get num samples() without validating that this count is consistent with the number of chunks in the chunks vector. Consequently, if the saiz box declares more samples than the chunks cover, the loop increments current chunk beyond the size of the chunks vector, leading to an out-of-bounds read. This is triggered during file parsing via the heif context read from file function without requiring user interaction.
Recommendations Update to version 1.22.0.

Exploit

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-12096
CVE-2026-41071
ECHO-0BD8-3C77-95C2
GHSA-XJ92-XJFF-H8W3
OPENSUSE-SU-2026:10878-1
OPENSUSE-SU-2026:20974-1
SUSE-SU-2026:22153-1
SUSE-SU-2026:2622-1
USN-8454-1

Affected Products

Linuxmint
Ubuntu
Libheif