USN-8526-1: libheif vulnerabilities
Xianrui Dong discovered that libheif had an out-of-bounds read in its HEIF sequence track parser. An attacker could possibly use this issue to cause a denial of service or obtain sensitive information. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-47254) Junyi Liu discovered that libheif had a null pointer dereference in its image tiling interface. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-47709) Calvin Young and Enoch Chow discovered that libheif had an integer overflow in its inline mask size calculation. An attacker could possibly use this issue to cause a denial of service or obtain sensitive information. (CVE-2026-47714) Ariel Koren discovered that libheif had an integer underflow in its grid image tile coordinate transform. An attacker could possibly use this issue to cause a denial of service or obtain sensitive information. (CVE-2026-48029) It was discovered that libheif had a missing bound check in its HEIF sequence parser, allowing unbounded heap allocation. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-50142)
CSIRTS triage
- What
- libheif has multiple vulnerabilities that could lead to denial of service or information disclosure.
- Who is affected
- Only Ubuntu 26.04 LTS deployments are affected.
- Urgency
- Remediation is urgent due to the potential for denial of service and information disclosure.
- Action
- Update to the latest version of libheif.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch libheif
Get an email when a new libheif advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://ubuntu.com/security/notices/USN-8526-1
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-472540.19% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 8% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-477090.21% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 11% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-477140.11% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 1% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-480290.30% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 23% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-501420.56% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 44% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-47254 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-47709 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-47714 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-48029 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-50142 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- highCVE-2026-50142: libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.0, a crafte…nvd
- highCVE-2026-48029: libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.19.0 through 1.21.2 hav…nvd
- mediumCVE-2026-47709: libheif is a HEIF and AVIF file format decoder and encoder. Versions prior to 1.22.0 crashes i…nvd
- mediumCVE-2026-47254: libheif is a HEIF and AVIF file format decoder and encoder. Prior to version 1.22.0, `Track::i…nvd
- mediumCVE-2026-47714: libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, the …nvd
- unknownUSN-8526-2: libheif vulnerabilitiesubuntu
More from Ubuntu Security Notices
- unknownUSN-8683-1: libheif vulnerabilities2026-08-26
- unknownUSN-8682-1: Bind vulnerabilities2026-08-26
- unknownUSN-8681-1: OpenJDK 25 vulnerabilities2026-08-26
- unknownUSN-8659-4: Linux kernel (Oracle) vulnerability2026-08-26
- unknownUSN-8666-2: Linux kernel (Azure) vulnerabilities2026-08-25