Echo: libheif: security update to 1.19.8-1+e4

high Tenable Self-Hosted Container Security Plugin ID 455606

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and prior contain a heap
buffer over-read in HeifPixelImage::overlay() in libheif/pixelimage.cc. When compositing an overlay image
(iovl) whose child image has a different bit depth for the alpha channel than for the color channels, the
function indexes into the alpha plane using the color channel stride (in_stride) instead of the previously
retrieved alpha_stride, causing reads past the end of the alpha buffer (up to 3,123 bytes for a 100×50
image with 10-bit color and 8-bit alpha). A crafted HEIF file can exploit this to cause a denial of
service (crash) or potentially disclose adjacent heap memory through leaked bytes embedded in the decoded
output pixels. This issue has been fixed in versionThis issue has been fixed in version 1.22.0.
(CVE-2026-32882)

Solution

Update the libheif library and its related packages to version 1.19.8-1+e4 or later.

See Also

https://advisory.echohq.com/cve/CVE-2026-32882

Plugin Details

Severity: High

ID: 455606

Version: Revision 1.1

Type: Local

Published: 10/1/2026

Updated: 10/1/2026

Risk Information

VPR

Risk Factor: Medium

Score: 5.5

Percentile: 95.86

CVSS v2

Risk Factor: High

Base Score: 8.5

Temporal Score: 6.3

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:C

CVSS Score Source: CVE-2026-32882

CVSS v3

Risk Factor: High

Base Score: 7.1

Temporal Score: 6.2

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 5/26/2026

Vulnerability Publication Date: 5/19/2026

Reference Information

CVE: CVE-2026-32882

IAVB: 2026-B-0158-S