CVE-2026-32738Disclosure(struktur / libheif)

LOWCVSS 6.5 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and below, a crafted 792-byte HEIF sequence file with samples_per_chunk=0 in the stsc box causes an unsigned integer underflow in the Chunk constructor (m_last_sample = 0 + 0 - 1 = UINT32_MAX), mapping all samples to an empty chunk and resulting in a denial of service. When any sample is accessed, the library reads from index 0 of an empty std::vector, causing a guaranteed SEGV (null-page read). The file parses successfully without producing an error; the crash occurs on the first frame access. This issue has been fixed in version 1.22.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-125CWE-476

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • libheif

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
libheif

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-05-19: 2Technical Details · 2026-05-19: 205-19
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-32738 Integer Underflow Denial of Service in libheif Versions 1.21.2 and Below https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-32738

    Post summary

    The post announces CVE‑2026‑32738, an integer underflow denial‑of‑service flaw in libheif (1.21.2 and earlier), but offers no PoC, exploit, active‑exploitation evidence, or patch information.

    0000055
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-32738 libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and below, a crafted 792-byte HEIF sequence file with samples_per_chunk=0 in the stsc b… https://www.cve.org/CVERecord?id=CVE-2026-32738

    Post summary

    The post discloses CVE-2026-32738 related to libheif, describing a crafted HEIF file that triggers a failure, but provides no PoC, exploit, or patch information.

    00000123
    57.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appstrukturlibheif---

Explore more