Search
Search is not available in local development.
Run npx pagefind --site __site after building to enable it.
JLSEC-2026-156 Medium 6.5

JLSEC-2026-156

JLSEC Published
Modified
Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Affected Packages
libheif_jll < 1.21.2000+0
Aliases / Upstream
CVE-2025-68431 EUVD-2025-205646

libheif is an HEIF and AVIF file format decoder and encoder. Prior to version 1.21.0, a crafted HEIF that exercises the overlay image item path triggers a heap buffer over-read in HeifPixelImage::overlay(). The function computes a negative row length (likely from an unclipped overlay rectangle or invalid offsets), which then underflows when converted to size_t and is passed to memcpy, causing a very large read past the end of the source plane and a crash. Version 1.21.0 contains a patch. As a workaround, avoid decoding images using iovl overlay boxes.

References