CVE-2026-62377

EUVD-2026-62191
libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.0 and earlier, a crafted HEIF sequence accepted by heif_context_read_from_memory() can leave the context with no registered sequence tracks and crash when heif_context_get_track(ctx, 0) is called. HeifContext::get_track() in libheif/context.cc executes assert(has_sequence()) before its normal error handling, so assert-enabled builds abort instead of allowing the public wrapper in libheif/api/libheif/heif_sequences.cc to return null. In release builds, removing the assertion lets the track_id zero path dereference m_tracks.begin()->second on an empty map, which is undefined behavior and typically crashes. The issue is reachable through documented public APIs after parsing attacker-controlled bytes. This issue is fixed in version 1.23.1.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
libheif-aom
suse enterprise desktop 15 SP7
1.23.1-150700.3.18.1
fixed
suse enterprise sap 15 SP7
1.23.1-150700.3.18.1
fixed
suse enterprise server 15 SP7
1.23.1-150700.3.18.1
fixed
libheif-dav1d
suse enterprise desktop 15 SP7
1.23.1-150700.3.18.1
fixed
suse enterprise sap 15 SP7
1.23.1-150700.3.18.1
fixed
suse enterprise server 15 SP7
1.23.1-150700.3.18.1
fixed
libheif-jpeg
suse enterprise desktop 15 SP7
1.23.1-150700.3.18.1
fixed
suse enterprise sap 15 SP7
1.23.1-150700.3.18.1
fixed
suse enterprise server 15 SP7
1.23.1-150700.3.18.1
fixed
libheif-rav1e
suse enterprise desktop 15 SP7
1.23.1-150700.3.18.1
fixed
suse enterprise sap 15 SP7
1.23.1-150700.3.18.1
fixed
suse enterprise server 15 SP7
1.23.1-150700.3.18.1
fixed
libheif1
suse enterprise desktop 15 SP7
1.23.1-150700.3.18.1
fixed
suse enterprise sap 15 SP7
1.23.1-150700.3.18.1
fixed
suse enterprise server 15 SP7
1.23.1-150700.3.18.1
fixed