CVE-2026-62292Disclosure

LOWCVSS 8.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.1, a crafted uncompressed HEIF image using generic zlib unci full-item compression can crash an application that decodes an advertised tile with heif_image_handle_decode_image_tile(). In libheif/codecs/uncompressed/unc_decoder.cc, unc_decoder::fetch_tile_data() computes a large tile offset and unc_decoder::get_compressed_image_data_uncompressed() validates it with range_start_offset plus range_size. For the last advertised tile (4095, 4095), the addition can wrap to zero, bypass the bounds check, and pass an invalid source pointer and a one-terabyte length to memcpy. The observed result is an out-of-bounds read and process crash; opening the file alone does not trigger the issue because tile decoding is required. This issue is fixed in version 1.23.1.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-125

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-08-18); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-08-18: 1Mentions · 2026-08-19: 1Patch / Workaround · 2026-08-19: 1Technical Details · 2026-08-18: 1Technical Details · 2026-08-19: 108-1808-19
Signal classification1 categories
Disclosure
2100.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-62292 libheif Out-of-Bounds Read and Crash via Crafted HEIF Image https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-62292

    Post summary

    The line announces CVE‑2026‑62292 as an out‑of‑bounds read and crash vulnerability in libheif triggered by a crafted HEIF image, with no additional PoC, exploit, or mitigation details.

    00010145
    4.1K followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨HIGH - libheif OOB Read Crash via HEIF Tile Decode Integer Wrap (CVE-2026-62292) libheif heif_image_handle_decode_image_tile() mishandles crafted uncompressed HEIF tiles: an integer wrap in tile range calculations bypasses a bounds check, leading to memcpy() reading out-of-bounds with an invalid pointer and huge length. Result: reliable process crash (DoS). 👉Affected: libheif >= 1.19.0, < 1.23.1 | Upgrade to 1.23.1

    Post summary

    The alert discloses CVE‑2026‑62292 in libheif, explains how an integer wrap leads to an OOB read and crash, and recommends upgrading to version 1.23.1.

    0000097
    292 followersView on X

Explore more