Description
A vulnerability was determined in strukturag libheif up to 1.21.2. This affects the function vvdec_push_data2 of the file libheif/plugins/decoder_vvdec.cc of the component HEIF File Parser. Executing a manipulation of the argument size can lead to out-of-bounds read. The attack needs to be launched locally. The exploit has been publicly disclosed and may be utilized. This patch is called b97c8b5f198b27f375127cd597a35f2113544d03. It is advisable to implement a patch to correct this issue.
Problem types
Product status
1.21.1
1.21.2
Timeline
| 2026-03-11: | Advisory disclosed |
| 2026-03-11: | VulDB entry created |
| 2026-03-11: | VulDB entry last update |
Credits
biniam (VulDB User)
References
vuldb.com/?id.350381 (VDB-350381 | strukturag libheif HEIF File decoder_vvdec.cc vvdec_push_data2 out-of-bounds)
vuldb.com/?ctiid.350381 (VDB-350381 | CTI Indicators (IOB, IOC, IOA))
vuldb.com/?submit.765979 (Submit #765979 | strukturag libheif 1.21.2 Out-of-Bounds Read)
github.com/strukturag/libheif/issues/1712
github.com/strukturag/libheif/issues/1712
github.com/biniamf/pocs/tree/main/libheif_vvdec
github.com/...ommit/b97c8b5f198b27f375127cd597a35f2113544d03
github.com/strukturag/libheif/