CVE-2026-47178

Public on 2026-06-20
Modified on 2026-06-20
Description
A critical heap-based buffer overflow vulnerability exists in libheif v1.21.2 (and likely earlier versions) within the handling of uncompressed HEIF images (ISO/IEC 23001-17, unci item type). When processing a tiled image with chroma subsampling (e.g., 4:2:0 or 4:2:2), the library fails to scale spatial offsets for the chroma planes. This leads to out-of-bounds memory writes when decoding any tile other than the top-left one, potentially resulting in remote code execution (RCE). (from https://project-zero.issues.chromium.org/issues/507396184)
Severity
Important severity
Important
See what this means
CVSS v3 Base Score
8.0
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 2023 libheif Pending Fix

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 8.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H