CVE-2026-3949
EUVD-2026-1130011.03.2026, 19:16
A vulnerability was determined in strukturag libheif up to 1.21.2. This affects the function vvdec_push_data2 of the file libheif/plugins/decoder_vvdec.cc of the component HEIF File Parser. Executing a manipulation of the argument size can lead to out-of-bounds read. The attack needs to be launched locally. The exploit has been publicly disclosed and may be utilized. This patch is called b97c8b5f198b27f375127cd597a35f2113544d03. It is advisable to implement a patch to correct this issue.Enginsight
Awaiting analysis
This vulnerability is currently awaiting analysis.
Ubuntu Releases
Common Weakness Enumeration
References