Vulnerability Description
libheif is a HEIF and AVIF file format decoder and encoder. Prior to version 1.22.1, the uncompressed HEIF decoder validates explicit icef compressed-unit offsets using unit_offset + unit_size. Because the addition can wrap, a crafted HEIF file can pass the range check and then construct a vector from iterators outside the compressed item buffer, producing an out-of-bounds heap read and crash. Version 1.22.1 patches the issue.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Struktur | Libheif | < 1.22.1 |
Related Weaknesses (CWE)
References
- https://github.com/strukturag/libheif/security/advisories/GHSA-r7qj-cg5r-r6vfMitigationVendor Advisory
- https://github.com/strukturag/libheif/security/advisories/GHSA-r7qj-cg5r-r6vfMitigationVendor Advisory
FAQ
What is CVE-2026-49271?
CVE-2026-49271 is a vulnerability with a CVSS score of 6.5 (MEDIUM). libheif is a HEIF and AVIF file format decoder and encoder. Prior to version 1.22.1, the uncompressed HEIF decoder validates explicit icef compressed-unit offsets using unit_offset + unit_size. Becaus...
How severe is CVE-2026-49271?
CVE-2026-49271 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-49271?
Check the references section above for vendor advisories and patch information. Affected products include: Struktur Libheif.