{"id":"MGASA-2026-0247","summary":"Updated libheif packages fix security vulnerabilities","details":"libheif has a Heap OOB Read/SEGV Crash via Zero samples_per_chunk.\n(CVE-2026-32738)\nlibheif is Vulnerable to Infinite Loop DoS via stts Sample Duration\nLookup. (CVE-2026-32739)\nHeap-Buffer-Overflow Write in Grid Tile Chroma Compositing.\n(CVE-2026-32740)\nlibheif has a heap buffer overflow in decode_mask_image().\n(CVE-2026-32741)\nUninitialized Heap Memory Information Leak via Failed Grid Tiles.\n(CVE-2026-32814)\nHeap Buffer OOB Read in overlay compositing due to wrong alpha stride.\n(CVE-2026-32882)\nstrukturag libheif stsz/stts track.cc load out-of-bounds.\n(CVE-2026-3950)\nlibheif allows Out-of-bounds vector access leading to invalid\ndereference (DoS). (CVE-2026-41069)\nHeap buffer over-read in SampleAuxInfoReader via crafted HEIF sequence\nfile with mismatched saiz sample count. (CVE-2026-41071)\nA critical heap-based buffer overflow vulnerability exists in libheif\nv1.21.2 (and likely earlier versions) within the handling of\nuncompressed HEIF images (ISO/IEC 23001-17, unci item type). When\nprocessing a tiled image with chroma subsampling (e.g., 4:2:0 or 4:2:2),\nthe library fails to scale spatial offsets for the chroma planes. This\nleads to out-of-bounds memory writes when decoding any tile other than\nthe top-left one, potentially resulting in remote code execution.\n(CVE-2026-47178)\nWrapped icef compressed-unit range check causes out-of-bounds read in\nuncompressed HEIF decoder. (CVE-2026-49271)\n","modified":"2026-07-13T21:30:06.564525905Z","published":"2026-07-13T21:24:46Z","upstream":["CVE-2026-32738","CVE-2026-32739","CVE-2026-32740","CVE-2026-32741","CVE-2026-32814","CVE-2026-32882","CVE-2026-3950","CVE-2026-41069","CVE-2026-41071","CVE-2026-47178","CVE-2026-49271"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2026-0247.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=35729"},{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-8454-1"},{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-8479-1"}],"affected":[{"package":{"name":"libheif","ecosystem":"Mageia:10","purl":"pkg:rpm/mageia/libheif?arch=source&distro=mageia-10"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.20.2-3.1.mga10"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2026-0247.json"}},{"package":{"name":"libheif","ecosystem":"Mageia:10","purl":"pkg:rpm/mageia/libheif?arch=source&distro=mageia-10"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.20.2-3.1.mga10.tainted"}]}],"ecosystem_specific":{"section":"tainted"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2026-0247.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}