Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Ubuntu USN |
USN-7952-1 | libheif vulnerabilities |
Wed, 25 Feb 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:struktur:libheif:*:*:*:*:*:*:*:* |
Mon, 05 Jan 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Struktur
Struktur libheif |
|
| Vendors & Products |
Struktur
Struktur libheif |
Tue, 30 Dec 2025 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 29 Dec 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | libheif is an HEIF and AVIF file format decoder and encoder. Prior to version 1.21.0, a crafted HEIF that exercises the overlay image item path triggers a heap buffer over-read in `HeifPixelImage::overlay()`. The function computes a negative row length (likely from an unclipped overlay rectangle or invalid offsets), which then underflows when converted to `size_t` and is passed to `memcpy`, causing a very large read past the end of the source plane and a crash. Version 1.21.0 contains a patch. As a workaround, avoid decoding images using `iovl` overlay boxes. | |
| Title | libheif has Potential Heap Buffer Over-Read | |
| Weaknesses | CWE-125 CWE-190 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-12-30T22:26:20.374Z
Reserved: 2025-12-17T15:29:39.380Z
Link: CVE-2025-68431
Updated: 2025-12-30T21:54:36.793Z
Status : Analyzed
Published: 2025-12-29T19:15:56.933
Modified: 2026-02-25T14:53:34.747
Link: CVE-2025-68431
No data.
OpenCVE Enrichment
Updated: 2026-01-05T10:23:13Z
Ubuntu USN