CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-47254

mediumCVSS 6.1covered by 2 sourcesfirst seen 2026-07-09
libheif is a HEIF and AVIF file format decoder and encoder. Prior to version 1.22.0, Track::init_sample_timing_table() in libheif/sequences/track.cc stores an out-of-bounds chunk index (m_chunks.size()) into m_presentation_timeline when the number of chunks defined in the stco box is less than the number of samples in stsz. A subsequent call to heif_track_get_next_raw_sequence_sample() reads m_chunks[chunk_idx] with that OOB index, causing a heap-buffer-overflow. Version 1.22.0 fixes the issue.

CSIRTS triage

What
libheif has multiple vulnerabilities that could lead to denial of service or information disclosure.
Who is affected
Only Ubuntu 26.04 LTS deployments are affected.
Urgency
Remediation is urgent due to the potential for denial of service and information disclosure.
Action
Update to the latest version of libheif.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-47254

Get an email if CVE-2026-47254 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-47254

CVE.org record

Embed the live status

CVE-2026-47254 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-47254 status](https://www.csirts.com/badge/CVE-2026-47254)](https://www.csirts.com/cve/CVE-2026-47254)