UBUNTU-CVE-2025-68431
Dashboard / Vulnerabilities / UBUNTU-CVE-2025-68431
UBUNTU-CVE-2025-68431
Summary:
Details: libheif is an HEIF and AVIF file format decoder and encoder. Prior to version 1.21.0, a crafted HEIF that exercises the overlay image item path triggers a heap buffer over-read in `HeifPixelImage::overlay()`. The function computes a negative row length (likely from an unclipped overlay rectangle or invalid offsets), which then underflows when converted to `size_t` and is passed to `memcpy`, causing a very large read past the end of the source plane and a crash. Version 1.21.0 contains a patch. As a workaround, avoid decoding images using `iovl` overlay boxes.
References: https://ubuntu.com/security/CVE-2025-68431, https://www.cve.org/CVERecord?id=CVE-2025-68431, https://github.com/strukturag/libheif/security/advisories/GHSA-j87x-4gmq-cqfq, https://github.com/strukturag/libheif/releases/tag/v1.21.0, https://ubuntu.com/security/notices/USN-7952-1
Affected packages
Package
Name: libheif
Purl: pkg:deb/ubuntu/libheif?arch=source&distro=esm-apps%2Fbionic
Affected ranges
Type: ECOSYSTEM
Events:
