CVE-2026-3950
Gravedad CVSS v4.0:
MEDIA
Tipo:
CWE-119
Restricción de operaciones inapropiada dentro de los límites del búfer de la memoria
Fecha de publicación:
11/03/2026
Última modificación:
11/03/2026
Descripción
*** Pendiente de traducción *** A vulnerability was identified in strukturag libheif up to 1.21.2. This impacts the function Track::load of the file libheif/sequences/track.cc of the component stsz/stts. The manipulation leads to out-of-bounds read. The attack needs to be performed locally. The exploit is publicly available and might be used. Applying a patch is the recommended action to fix this issue. The patch available is inofficial and not approved yet.
Impacto
Puntuación base 4.0
4.80
Gravedad 4.0
MEDIA
Puntuación base 3.x
3.30
Gravedad 3.x
BAJA
Puntuación base 2.0
1.70
Gravedad 2.0
BAJA
Referencias a soluciones, herramientas e información
- https://github.com/Niebelungen-D/pocs/tree/main/heif_dec_sequence_chunk_idx_oob
- https://github.com/strukturag/libheif/
- https://github.com/strukturag/libheif/issues/1715
- https://github.com/strukturag/libheif/pull/1721
- https://vuldb.com/?ctiid_350382=
- https://vuldb.com/?id_350382=
- https://vuldb.com/?submit_766431=



