Description
A vulnerability was identified in strukturag libheif up to 1.21.2. This impacts the function Track::load of the file libheif/sequences/track.cc of the component stsz/stts. The manipulation leads to out-of-bounds read. The attack needs to be performed locally. The exploit is publicly available and might be used. Applying a patch is the recommended action to fix this issue. The patch available is inofficial and not approved yet.
Problem types
Product status
1.21.1
1.21.2
Timeline
| 2026-03-11: | Advisory disclosed |
| 2026-03-11: | VulDB entry created |
| 2026-03-11: | VulDB entry last update |
Credits
Niebelungen (VulDB User)
References
vuldb.com/?id.350382 (VDB-350382 | strukturag libheif stsz/stts track.cc load out-of-bounds)
vuldb.com/?ctiid.350382 (VDB-350382 | CTI Indicators (IOB, IOC, IOA))
vuldb.com/?submit.766431 (Submit #766431 | strukturag libheif 1.21.2 Out-of-Bounds Read)
github.com/strukturag/libheif/issues/1715
github.com/...pocs/tree/main/heif_dec_sequence_chunk_idx_oob
github.com/strukturag/libheif/pull/1721
github.com/strukturag/libheif/