Junglewise Threat Intelligence

CVE-2026-41071: Strukturag libheif heap buffer over-read in SampleAuxInfoReader

CVE-2026-41071 · Severity: info · CVSS 5.1 · Published 2026-05-22

Technologies: struktur AG Libheif, Strukturag Libheif. Vendors: struktur AG, Strukturag.

Executive brief

libheif is an open-source library used to decode and encode HEIF and AVIF image files, commonly used in photo viewers and web applications. A vulnerability exists where a specially crafted image file can cause the software to read memory outside of its intended boundaries. This can lead to an immediate application crash (denial of service) or potentially allow an attacker to read sensitive information from the system's memory.

Technical details

An out-of-bounds read vulnerability exists in libheif's SampleAuxInfoReader constructor within libheif/sequences/track.cc. The root cause is a lack of validation between the sample count declared in the 'saiz' box and the actual number of chunks available in the track's chunk table. When a crafted HEIF file specifies more samples than chunks, the parsing loop increments the chunk index beyond the bounds of the chunks vector. In release builds where assertions are disabled, this leads to an out-of-bounds read. The vulnerability is triggered during file parsing via heif_context_read_from_file and can result in information disclosure or a denial of service (crash). This issue is fixed in version 1.22.0.

Affected products

  • strukturag libheif <= 1.21.2

Timeline

  • 2026-05-19: patched: Fixed in version 1.22.0
  • 2026-05-19: advisory: GitHub Security Advisory published
  • 2026-05-22: disclosed: CVE-2026-41071 published to NVD

References

Related threats