Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 13 Mar 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Thu, 12 Mar 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Struktur
Struktur libheif |
|
| Vendors & Products |
Struktur
Struktur libheif |
Wed, 11 Mar 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 11 Mar 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was identified in strukturag libheif up to 1.21.2. This impacts the function Track::load of the file libheif/sequences/track.cc of the component stsz/stts. The manipulation leads to out-of-bounds read. The attack needs to be performed locally. The exploit is publicly available and might be used. Applying a patch is the recommended action to fix this issue. The patch available is inofficial and not approved yet. | |
| Title | strukturag libheif stsz/stts track.cc load out-of-bounds | |
| Weaknesses | CWE-119 CWE-125 |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-03-11T20:24:59.822Z
Reserved: 2026-03-11T12:02:54.833Z
Link: CVE-2026-3950
Updated: 2026-03-11T20:24:48.393Z
Status : Deferred
Published: 2026-03-11T20:16:22.567
Modified: 2026-04-29T01:00:01.613
Link: CVE-2026-3950
OpenCVE Enrichment
Updated: 2026-03-20T15:29:25Z