What is CVE-2026-47714?
An integer overflow vulnerability exists in the mask parsing code of libheif's region.cc, affecting versions 1.21.2 and prior. The product of parsed width and height values can exceed the maximum limit for an unsigned 32-bit integer. Users should update to the latest version to mitigate the risk.
Azərbaycanca: libheif kitabxanasında region.cc faylında HEIF fayllarından maska ölçülərini oxuyarkən tam ədəd daşması (integer overflow) baş verə bilər. Bu, 1.21.2 və daha əvvəlki versiyalara təsir edir. İstifadəçilərə kitabxananı ən son versiyaya yeniləmələri tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-190
FAQ2
Which versions of libheif are affected by the integer overflow vulnerability?
The CVE-2026-47714 vulnerability affects libheif versions 1.21.2 and prior.
What is the recommended mitigation for the libheif vulnerability?
Users are advised to update the library to the latest version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.