CVE-2026-32741: high-severity vulnerability in strukturag libheif
libheif has a heap buffer overflow in decode_mask_image()
Published · Updated
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.1epss 0.4%
exploitation probability
0.4%top 63% of all CVEs
observed exploitation
nono source reports it
libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and below contain a heap buffer overflow in MaskImageCodec::decode_mask_image(). When decoding a HEIF file containing a mask image (mski), the function copies the full iloc extent data into a pixel buffer using memcpy(dst, data.data(), data.size()). The copy length data.size() is determined by the iloc extent in the file (attacker-controlled), while the destination buffer is sized based on the declared image dimensions. Because no upper-bound check exists on the data length, a crafted file whose iloc extent exceeds the pixel buffer allocation overflows the heap. The vulnerable single-memcpy branch is reached when the mskC property specifies bits_per_pixel = 8 and the ispe property declares an even width ≥ 64 (so that stride == width), with no changes to default security limits or external codec plugins required. This issue has been fixed in version 1.22.0.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H
Affected products
strukturag · libheifRelated CVEs — strukturag libheif
In the same product, most dangerous first.
CVE-2026-32740HIGHlibheif: Heap-Buffer-Overflow Write in Grid Tile Chroma CompositingEPSS 0.8%CVE-2026-32882HIGHlibheif: Heap Buffer OOB Read in overlay compositing due to wrong alpha strideEPSS 0.7%CVE-2026-50142HIGHlibheif: unbounded heap allocation in HEIF sequence parser (stsz fixed-size mode missing bound check)EPSS 0.7%CVE-2026-84383CRITICALlibheif: Heap buffer overflow in `scale_nearest_neighbor()` via duplicate Alpha planes from nested `iden`/`auxl` itemsEPSS 0.6%CVE-2026-62292HIGHlibheif: Out-of-bounds read in uncompressed unci tile range slicingEPSS 0.5%CVE-2026-84447HIGHlibheif: Derived-image indirect reference chains and tiled offsets bypass decode caching and MemoryHandle limits, causing CPU/memory amplification DoSEPSS 0.5%
References
https://access.redhat.com/security/cve/CVE-2026-32741https://bugzilla.redhat.com/show_bug.cgi?id=2480002https://github.com/strukturag/libheif/releases/tag/v1.22.0https://github.com/strukturag/libheif/security/advisories/GHSA-j3w5-7whq-p37qhttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32741.json