Vulnerability Description
libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, a malformed HEIF sequence file can trigger an out-of-bounds read in core sequence parsing logic, causing DoS. A malformed file can have stco.entry_count == 0 (creating no chunks) while still passing validation because saio.entry_count == 0 matches, but with saiz.sample_count > 0 the SampleAuxInfoReader constructor still enters its loop. This leads to an out-of-bounds dereference on the empty chunks[0] in chunked mode.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Struktur | Libheif | < 1.22.0 |
Related Weaknesses (CWE)
References
- https://github.com/strukturag/libheif/releases/tag/v1.22.0ProductRelease Notes
- https://github.com/strukturag/libheif/security/advisories/GHSA-p82x-fpmv-576rExploitVendor Advisory
- https://github.com/strukturag/libheif/security/advisories/GHSA-p82x-fpmv-576rExploitVendor Advisory
FAQ
What is CVE-2026-41069?
CVE-2026-41069 is a vulnerability with a CVSS score of 6.5 (MEDIUM). libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, a malformed HEIF sequence file can trigger an out-of-bounds read in core sequence parsing logic, causing DoS. ...
How severe is CVE-2026-41069?
CVE-2026-41069 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-41069?
Check the references section above for vendor advisories and patch information. Affected products include: Struktur Libheif.