CVE-2025-68431

⚪ Do wiadomości

Przepełnienie bufora w libheif umożliwia awarię aplikacji przy przetwarzaniu złośliwych obrazów.

CVSS
6.5
EPSS
0.4%
Exploit
poc
Vendor
struktur
Opis źródłowy (NVD)

libheif is an HEIF and AVIF file format decoder and encoder. Prior to version 1.21.0, a crafted HEIF that exercises the overlay image item path triggers a heap buffer over-read in `HeifPixelImage::overlay()`. The function computes a negative row length (likely from an unclipped overlay rectangle or invalid offsets), which then underflows when converted to `size_t` and is passed to `memcpy`, causing a very large read past the end of the source plane and a crash. Version 1.21.0 contains a patch. As a workaround, avoid decoding images using `iovl` overlay boxes.

exploit Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS6.5
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.4%
Opublikowano (NVD)2025-12-29 19:15:56 UTC
Ostatnia modyfikacja (NVD)2026-10-07 12:10:00 UTC
Referencje