CVE-2026-32740

libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and prior contain a heap-buffer-overflow (write) vulnerability in the grid tile compositing, allowing an attacker to write 64 bytes of fully attacker-controlled data past the end of a chroma plane heap allocation by crafting a HEIF/AVIF file with a 1×4 grid of odd-height tiles. The overflow is triggered during normal image decoding with default build configuration. The written bytes are chroma (Cb/Cr) pixel values from the attacking tile, giving the attacker full control over the overflow content. This issue has been fixed in version 1.22.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:struktur:libheif:*:*:*:*:*:*:*:*

History

24 Jul 2026, 09:10

Type Values Removed Values Added
Summary
  • (es) libheif es un decodificador y codificador de formato de archivo HEIF y AVIF. Las versiones 1.21.2 y anteriores contienen una vulnerabilidad de desbordamiento de búfer de montón (escritura) en la composición de mosaicos de cuadrícula, permitiendo a un atacante escribir 64 bytes de datos totalmente controlados por el atacante más allá del final de una asignación de montón del plano de croma al crear un archivo HEIF/AVIF con una cuadrícula de 1×4 de mosaicos de altura impar. El desbordamiento se activa durante la decodificación normal de la imagen con la configuración de compilación predeterminada. Los bytes escritos son valores de píxeles de croma (Cb/Cr) del mosaico atacante, dando al atacante control total sobre el contenido del desbordamiento. Este problema ha sido solucionado en la versión 1.22.0.

30 Jun 2026, 03:18

Type Values Removed Values Added
References
  • () https://access.redhat.com/security/cve/CVE-2026-32740 -
  • () https://bugzilla.redhat.com/show_bug.cgi?id=2479969 -
  • () https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32740.json -

21 May 2026, 14:16

Type Values Removed Values Added
References () https://github.com/strukturag/libheif/security/advisories/GHSA-frfr-f3vg-2g6j - Exploit, Vendor Advisory () https://github.com/strukturag/libheif/security/advisories/GHSA-frfr-f3vg-2g6j - Exploit, Vendor Advisory

20 May 2026, 14:17

Type Values Removed Values Added
CPE cpe:2.3:a:struktur:libheif:*:*:*:*:*:*:*:*
First Time Struktur
Struktur libheif
References () https://github.com/strukturag/libheif/releases/tag/v1.22.0 - () https://github.com/strukturag/libheif/releases/tag/v1.22.0 - Release Notes
References () https://github.com/strukturag/libheif/security/advisories/GHSA-frfr-f3vg-2g6j - () https://github.com/strukturag/libheif/security/advisories/GHSA-frfr-f3vg-2g6j - Exploit, Vendor Advisory

19 May 2026, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-19 20:16

Updated : 2026-07-24 09:10


NVD link : CVE-2026-32740

Mitre link : CVE-2026-32740

CVE.ORG link : CVE-2026-32740


JSON object : View

Products Affected

struktur

  • libheif
CWE
CWE-787

Out-of-bounds Write