PT-2025-53782 · Libheif+4 · Libheif+4

·

CVE-2025-68431

·

Published

2025-12-29

·

Updated

2026-07-06

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions libheif versions prior to 1.21.0
Description libheif is a decoder and encoder for HEIF and AVIF file formats. A specially crafted HEIF file that utilizes the overlay image item path can cause a heap buffer over-read in the HeifPixelImage::overlay() function. The function calculates a negative row length, which results in an underflow when converted to size t and is subsequently used in a memcpy operation. This leads to a read past the end of the source plane and a crash. The vulnerable function is HeifPixelImage::overlay(). As a workaround, avoid decoding images that use iovl overlay boxes.
Recommendations Update to version 1.21.0 or later. As a temporary workaround, avoid decoding images using iovl overlay boxes.

Exploit

Fix

DoS

Out of bounds Read

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-09348
CVE-2025-68431
ECHO-D777-8AFD-DE52
GHSA-J87X-4GMQ-CQFQ
OPENSUSE-SU-2026:10019-1
OPENSUSE-SU-2026:20076-1
OPENSUSE-SU-2026:20974-1
SUSE-SU-2026:0087-1
SUSE-SU-2026:0377-1
SUSE-SU-2026:20121-1
SUSE-SU-2026:22153-1
SUSE-SU-2026:2622-1
USN-7952-1

Affected Products

Debian
Linuxmint
Red Os
Ubuntu
Libheif