CVE-2026-47254: CWE-125: Out-of-bounds Read in strukturag libheif
libheif is a HEIF and AVIF file format decoder and encoder. Prior to version 1.22.0, `Track::init_sample_timing_table()` in `libheif/sequences/track.cc` stores an out-of-bounds chunk index (`m_chunks.size()`) into `m_presentation_timeline` when the number of chunks defined in the `stco` box is less than the number of samples in `stsz`. A subsequent call to `heif_track_get_next_raw_sequence_sample()` reads `m_chunks[chunk_idx]` with that OOB index, causing a heap-buffer-overflow. Version 1.22.0 fixes the issue.
AI Analysis
Technical Summary
The vulnerability in strukturag libheif affects versions before 1.22.0 in the Track::init_sample_timing_table() function. When the number of chunks defined in the 'stco' box is less than the number of samples in 'stsz', the code stores an out-of-bounds chunk index equal to m_chunks.size() into m_presentation_timeline. Later, heif_track_get_next_raw_sequence_sample() reads from m_chunks using this invalid index, causing a heap-buffer-overflow. This can lead to memory corruption and potential denial of service. The issue is resolved in libheif version 1.22.0.
Potential Impact
The heap-buffer-overflow caused by the out-of-bounds read can result in memory corruption and application crashes, impacting availability. Confidentiality and integrity impacts are rated low. The vulnerability requires local access (AV:L) and user interaction (UI:R) but no privileges (PR:N).
Mitigation Recommendations
Upgrade to libheif version 1.22.0 or later, where this vulnerability is fixed. Patch status is not explicitly confirmed in the vendor advisory, but version 1.22.0 is stated as the fixed version. No other mitigations are indicated.
CVE-2026-47254: CWE-125: Out-of-bounds Read in strukturag libheif
Description
libheif is a HEIF and AVIF file format decoder and encoder. Prior to version 1.22.0, `Track::init_sample_timing_table()` in `libheif/sequences/track.cc` stores an out-of-bounds chunk index (`m_chunks.size()`) into `m_presentation_timeline` when the number of chunks defined in the `stco` box is less than the number of samples in `stsz`. A subsequent call to `heif_track_get_next_raw_sequence_sample()` reads `m_chunks[chunk_idx]` with that OOB index, causing a heap-buffer-overflow. Version 1.22.0 fixes the issue.
CVSS v3.1
Score 6.1medium
Affected software
pkg:github/strukturag/libheifRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in strukturag libheif affects versions before 1.22.0 in the Track::init_sample_timing_table() function. When the number of chunks defined in the 'stco' box is less than the number of samples in 'stsz', the code stores an out-of-bounds chunk index equal to m_chunks.size() into m_presentation_timeline. Later, heif_track_get_next_raw_sequence_sample() reads from m_chunks using this invalid index, causing a heap-buffer-overflow. This can lead to memory corruption and potential denial of service. The issue is resolved in libheif version 1.22.0.
Potential Impact
The heap-buffer-overflow caused by the out-of-bounds read can result in memory corruption and application crashes, impacting availability. Confidentiality and integrity impacts are rated low. The vulnerability requires local access (AV:L) and user interaction (UI:R) but no privileges (PR:N).
Mitigation Recommendations
Upgrade to libheif version 1.22.0 or later, where this vulnerability is fixed. Patch status is not explicitly confirmed in the vendor advisory, but version 1.22.0 is stated as the fixed version. No other mitigations are indicated.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-05-18T22:54:18.273Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a5fe6d29c2644c7f8cb0a28
Added to database: 07/21/2026, 21:38:26 UTC
Last enriched: 07/22/2026, 08:54:44 UTC
Last updated: 07/31/2026, 19:22:59 UTC
Views: 14
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.