CVE-2026-47709
libheif is a HEIF and AVIF file format decoder and encoder. Versions prior to 1.22.0 crashes in the public C API heif_image_handle_get_image_tiling() when a malformed uncompressed HEIF image item has an associated uncC property but no associated ispe property. In debug builds this trips the ispe && uncC assertion in ImageItem_uncompressed::get_heif_image_tiling(). In a release/NDEBUG ASan build, the same file causes a null pointer read at address 0xa8. Version 1.22.0 fixes the issue.
CSIRTS triage
- What
- libheif has vulnerabilities that could lead to denial of service or information disclosure.
- Who is affected
- Deployments of libheif in Ubuntu 24.04 LTS are affected.
- Urgency
- Remediation is necessary due to potential denial of service and information exposure.
- Action
- Update to the latest version of libheif.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-47709
Get an email if CVE-2026-47709 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.21% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 11% of all EPSS-scored CVEs.
Advisory coverage (3)
- mediumCVE-2026-47709: libheif is a HEIF and AVIF file format decoder and encoder. Versions prior to 1.22.0 crashes i…nvd · 2026-07-21
- unknownUSN-8526-2: libheif vulnerabilitiesubuntu · 2026-07-14
- unknownUSN-8526-1: libheif vulnerabilitiesubuntu · 2026-07-09
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-47709)