CVE-2026-3949

A vulnerability was determined in strukturag libheif up to 1.21.2. This affects the function vvdec_push_data2 of the file libheif/plugins/decoder_vvdec.cc of the component HEIF File Parser. Executing a manipulation of the argument size can lead to out-of-bounds read. The attack needs to be launched locally. The exploit has been publicly disclosed and may be utilized. This patch is called b97c8b5f198b27f375127cd597a35f2113544d03. It is advisable to implement a patch to correct this issue.
Configurations

No configuration.

History

22 Apr 2026, 21:30

Type Values Removed Values Added
Summary
  • (es) Se determinó una vulnerabilidad en strukturag libheif hasta la versión 1.21.2. Esto afecta a la función vvdec_push_data2 del archivo libheif/plugins/decoder_vvdec.cc del componente HEIF File Parser. Ejecutar una manipulación del argumento size puede llevar a una lectura fuera de límites. El ataque debe lanzarse localmente. El exploit ha sido divulgado públicamente y puede ser utilizado. Este parche se llama b97c8b5f198b27f375127cd597a35f2113544d03. Es aconsejable implementar un parche para corregir este problema.

11 Mar 2026, 19:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-11 19:16

Updated : 2026-04-29 01:00


NVD link : CVE-2026-3949

Mitre link : CVE-2026-3949

CVE.ORG link : CVE-2026-3949


JSON object : View

Products Affected

No product.

CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer

CWE-125

Out-of-bounds Read