Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-47178

Gravedad CVSS v3.1:
MEDIA
Tipo:
CWE-787 Escritura fuera de límites
Fecha de publicación:
21/07/2026
Última modificación:
27/07/2026

Descripción

*** Pendiente de traducción *** libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.19.0 through 1.21.2, a crafted HEIF file (uncompressed `unci` codec, tiled, component-interleaved, 4:2:0) triggers a heap out-of-bounds write in libheif's uncompressed tile decoder. The write overwrites the C++ vtable pointer of an adjacent `unc_decoder_component_interleave` object; the next virtual call dispatches to an attacker-chosen address. Version 1.22.0 patches the issue.

Productos y versiones vulnerables

CPE Desde Hasta
cpe:2.3:a:struktur:libheif:*:*:*:*:*:*:*:* 1.19.0 (incluyendo) 1.22.0 (excluyendo)


Referencias a soluciones, herramientas e información