CVE-2026-47709

libheif is a HEIF and AVIF file format decoder and encoder. Versions prior to 1.22.0 crashes in the public C API `heif_image_handle_get_image_tiling()` when a malformed uncompressed HEIF image item has an associated `uncC` property but no associated `ispe` property. In debug builds this trips the `ispe && uncC` assertion in `ImageItem_uncompressed::get_heif_image_tiling()`. In a release/NDEBUG ASan build, the same file causes a null pointer read at address `0xa8`. Version 1.22.0 fixes the issue.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
UNKNOWN
---
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Debian logo
Debian Releases
Debian Product
Codename
libheif
bookworm
vulnerable
bookworm (security)
vulnerable
bullseye
vulnerable
bullseye (security)
vulnerable
forky
vulnerable
sid
1.23.1-1
fixed
trixie
vulnerable
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libheif
bionic
not-affected
focal
not-affected
jammy
not-affected
noble
Fixed 1.17.6-1ubuntu4.6
released
questing
Fixed 1.20.2-1ubuntu0.6
released
resolute
Fixed 1.21.2-3ubuntu0.3
released
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
libheif-aom
suse enterprise desktop 15 SP7
1.23.0-150700.3.15.1
fixed
suse enterprise sap 15 SP7
1.23.0-150700.3.15.1
fixed
suse enterprise server 15 SP7
1.23.0-150700.3.15.1
fixed
libheif-dav1d
suse enterprise desktop 15 SP7
1.23.0-150700.3.15.1
fixed
suse enterprise sap 15 SP7
1.23.0-150700.3.15.1
fixed
suse enterprise server 15 SP7
1.23.0-150700.3.15.1
fixed
libheif-jpeg
suse enterprise desktop 15 SP7
1.23.0-150700.3.15.1
fixed
suse enterprise sap 15 SP7
1.23.0-150700.3.15.1
fixed
suse enterprise server 15 SP7
1.23.0-150700.3.15.1
fixed
libheif-rav1e
suse enterprise desktop 15 SP7
1.23.0-150700.3.15.1
fixed
suse enterprise sap 15 SP7
1.23.0-150700.3.15.1
fixed
suse enterprise server 15 SP7
1.23.0-150700.3.15.1
fixed
libheif1
suse enterprise desktop 15 SP7
1.23.0-150700.3.15.1
fixed
suse enterprise sap 15 SP7
1.23.0-150700.3.15.1
fixed
suse enterprise server 15 SP7
1.23.0-150700.3.15.1
fixed
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
heif-pixbuf-loader
Amazon Linux 2023
0:1.19.8-1.amzn2023.0.7
fixed
heif-pixbuf-loader-debuginfo
Amazon Linux 2023
0:1.19.8-1.amzn2023.0.7
fixed
libheif
Amazon Linux 2023
0:1.19.8-1.amzn2023.0.7
fixed
libheif-debuginfo
Amazon Linux 2023
0:1.19.8-1.amzn2023.0.7
fixed
libheif-debugsource
Amazon Linux 2023
0:1.19.8-1.amzn2023.0.7
fixed
libheif-devel
Amazon Linux 2023
0:1.19.8-1.amzn2023.0.7
fixed
libheif-tools
Amazon Linux 2023
0:1.19.8-1.amzn2023.0.7
fixed
libheif-tools-debuginfo
Amazon Linux 2023
0:1.19.8-1.amzn2023.0.7
fixed