PatchSiren

strukturag CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH strukturag CVE published 2026-07-22

CVE-2026-48029

libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.19.0 through 1.21.2 have a heap OOB read in ImageItem_Grid::decode_grid_tile via irot-induced tile-coordinate underflow. Version 1.22.0 fixes the issue. This vulnerability affects users of libheif 1.19.0 through 1.21.2, who should update to version 1.22.0 to address the heap OOB read vulnerability. The vulnerability has been addressed, [truncated]

MEDIUM strukturag CVE published 2026-07-21

CVE-2026-47709

libheif is a HEIF and AVIF file format decoder and encoder. A vulnerability in the public C API `heif_image_handle_get_image_tiling()` causes a crash when a malformed uncompressed HEIF image item has an associated `uncC` property but no associated `ispe` property. This vulnerability affects users of libheif library, particularly those using versions prior to 1.22.0. The vulnerability has a CVSS score of 6 [truncated]

MEDIUM strukturag CVE published 2026-07-21

CVE-2026-47254

CVE-2026-47254 is a MEDIUM severity vulnerability in libheif, a HEIF and AVIF file format decoder and encoder. The vulnerability causes a heap-buffer-overflow. AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:17:12.957Z and has not been modified since then. This vulnerability affects users of libheif who have not upgraded to version 1.22.0 o [truncated]

MEDIUM strukturag CVE published 2026-07-21

CVE-2026-47251

CVE-2026-47251 is a MEDIUM severity vulnerability in libheif, a HEIF and AVIF file format decoder and encoder. The vulnerability is caused by an integer overflow in a security check added to fix CVE-2026-3949. This allows a crafted HEIF file with a VVC track to trigger an out-of-bounds heap read. The issue was introduced in commit `b97c8b5` and PR #1712, which was closed as fixed without testing edge case [truncated]

HIGH strukturag CVE published 2026-07-21

CVE-2026-47247

CVE-2026-47247 is a high-severity vulnerability in libheif, a HEIF and AVIF file format decoder and encoder. An attacker can exploit this vulnerability to leak process heap memory as visible pixel values in decoded grid images. The vulnerability has been fixed in version 1.22.0. Affected users should update to the latest version and validate and sanitize input files.

MEDIUM strukturag CVE published 2026-07-21

CVE-2026-47178

A heap out-of-bounds write vulnerability exists in libheif's uncompressed tile decoder. Versions 1.19.0 through 1.21.2 are affected. A crafted HEIF file (uncompressed `unci` codec, tiled, component-interleaved, 4:2:0) can trigger the vulnerability. The write overwrites the C++ vtable pointer of an adjacent `unc_decoder_component_interleave` object; the next virtual call dispatches to an attacker-chosen ad [truncated]

MEDIUM strukturag CVE published 2026-07-21

CVE-2026-47714

CVE-2026-47714 is a MEDIUM severity vulnerability in libheif, a HEIF and AVIF file format decoder and encoder. An integer overflow in the inline mask parsing in `libheif/region.cc` can lead to out-of-bounds memory access. The issue was patched in version 1.22.0. Affected users should update to version 1.22.0 or later to address the vulnerability. The vulnerability has been publicly disclosed and may be su [truncated]

MEDIUM strukturag CVE published 2026-07-21

CVE-2026-45383

A heap buffer overflow vulnerability exists in libde265, an open-source implementation of the h.265 video codec, in versions prior to 1.0.19. The issue arises in the `decoder_context::decode_slice_unit_WPP()` function in `libde265/decctx.cc` when decoding a WPP (Wavefront Parallel Processing) HEVC slice. Specifically, `ctbAddrRS` is computed as `ctbRow * ctbsWidth` within the entry-point loop. If the PPS/ [truncated]

HIGH strukturag CVE published 2026-06-19

CVE-2026-49346

CVE-2026-49346 is a buffer overflow vulnerability in libde265, an open-source H.265 video codec implementation. A crafted H.265 bitstream with large SPS dimensions and 16-bit bit depth can cause a signed integer overflow, leading to a heap buffer overflow. This issue was patched in version 1.1.0. Defenders should assess their exposure and prioritize patching due to the high CVSS score of 7.1.

HIGH strukturag CVE published 2026-06-19

CVE-2026-49295

CVE-2026-49295 is a HIGH severity vulnerability in libde265, an open-source H.265 video codec implementation. A crafted H.265 bitstream can cause an out-of-bounds array write in `decoder_context::process_reference_picture_set()`. This occurs due to a missing aggregate bound check on predicted short-term reference picture set entries. The vulnerability has a CVSS score of 7.1 and was published on June 19, [truncated]

MEDIUM strukturag CVE published 2026-05-22

CVE-2026-41071

A heap-buffer-overflow vulnerability in libheif versions 1.21.2 and prior allows out-of-bounds reads when parsing crafted HEIF sequence files. The root cause is a missing validation between the sample count declared in the `saiz` box and the actual number of chunks in the track's chunk table. The `SampleAuxInfoReader` constructor iterates over `saiz->get_num_samples()` without verifying this count against [truncated]

MEDIUM strukturag CVE published 2026-05-22

CVE-2026-41069

## Summary libheif ≤1.21.2 contains an out-of-bounds read in its HEIF/AVIF sequence-parsing logic. A malformed file with `stco.entry_count == 0` (no chunks) but `saiz.sample_count > 0` causes the `SampleAuxInfoReader` constructor to dereference `chunks[0]` on an empty vector, resulting in denial of service. ## Affected Products - **Product:** libheif - **Versions:** 1.21.2 and prior - **Fixed in:** 1.22.0 [truncated]

HIGH strukturag CVE published 2026-05-19

CVE-2026-32882

CVE-2026-32882 is a heap buffer over-read in libheif’s overlay compositing path. A crafted HEIF file can trigger the flaw when the child image uses a different alpha-channel bit depth than its color channels. The issue can crash the decoder and may also leak adjacent heap data into output pixels. The vulnerability affects libheif 1.21.2 and earlier and is fixed in 1.22.0.

MEDIUM strukturag CVE published 2026-05-19

CVE-2026-32814

CVE-2026-32814 affects libheif versions 1.21.2 and earlier when decoding HEIF grid images with the default strict_decoding=false setting. A corrupted tile can fail without an error, leaving part of the output canvas unwritten and exposing uninitialized heap memory as decoded pixel data. The library still returns heif_error_Ok, so callers may trust output that contains heap garbage. The issue is fixed in l [truncated]

HIGH strukturag CVE published 2026-05-19

CVE-2026-32741

CVE-2026-32741 describes a heap buffer overflow in libheif’s mask image decoding path. A crafted HEIF file containing a mask image can cause MaskImageCodec::decode_mask_image() to copy attacker-controlled extent data into a destination buffer that was sized from the declared image dimensions, creating a heap overwrite. The issue is fixed in libheif 1.22.0.

HIGH strukturag CVE published 2026-05-19

CVE-2026-32740

CVE-2026-32740 is a high-severity heap-buffer-overflow write in libheif’s grid tile compositing path. A crafted HEIF/AVIF file with a 1×4 grid of odd-height tiles can trigger a write of attacker-controlled chroma data past the end of a heap allocation during normal decoding. The issue affects libheif 1.21.2 and earlier and is fixed in 1.22.0.

MEDIUM strukturag CVE published 2026-05-19

CVE-2026-32738

CVE-2026-32738 is a denial-of-service issue in libheif. A crafted HEIF sequence file can be parsed without error, but later trigger a crash when sample data is accessed. The supplied record says the issue was published on 2026-05-19 and fixed in libheif 1.22.0.