CVE-2025-68431Medium· 6.5▾ Sunlitlibheif is an HEIF and AVIF file format decoder and encoder. Prior to version 1.21.0, a crafted HEIF that exercises the overlay image item path triggers a heap buffer over-read in `HeifPixelImage::overlay()`. The function computes a nega…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.4%
libheif is an HEIF and AVIF file format decoder and encoder. Prior to version 1.21.0, a crafted HEIF that exercises the overlay image item path triggers a heap buffer over-read in HeifPixelImage::overlay(). The function computes a negative row length (likely from an unclipped overlay rectangle or invalid offsets), which then underflows when converted to size_t and is passed to memcpy, causing a very large read past the end of the source plane and a crash. Version 1.21.0 contains a patch. As a workaround, avoid decoding images using iovl overlay boxes.
libheif < 1.21.0Upgrade past the affected range:
libheif 1.21.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-84449Low· 3.7libheif is a HEIF and AVIF file format decoder and encoder
CVE-2026-84451Medium· 6.5libheif is a HEIF and AVIF file format decoder and encoder
CVE-2026-84448Medium· 4.0libheif is a HEIF and AVIF file format decoder and encoder
CVE-2026-41071High· 8.1libheif is a HEIF and AVIF file format decoder and encoder
CVE-2026-41069Medium· 6.5libheif is a HEIF and AVIF file format decoder and encoder
CVE-2026-84450Medium· 4.3libheif is a HEIF and AVIF file format decoder and encoder