Ubuntu 6947 Published by

A security issue was discovered in libheif, a library used to decode and encode HEIF and AVIF file formats. The vulnerability allowed an attacker to cause a denial of service or potentially execute arbitrary code on Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS systems. Aldo Ristori discovered another issue that also caused a denial of service on affected Ubuntu versions. To fix the issues, users can update their systems to the recommended package versions, which are available through standard system updates or Ubuntu Pro for certain releases.

[USN-7952-1] libheif vulnerabilities




[USN-7952-1] libheif vulnerabilities


==========================================================================
Ubuntu Security Notice USN-7952-1
January 12, 2026

libheif vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 25.10
- Ubuntu 25.04
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS

Summary:

Several security issues were fixed in libheif.

Software Description:
- libheif: An ISO/IEC 23008-12:2017 HEIF and AVIF file format decoder and encoder

Details:

It was discovered that libheif did not correctly handle certain memory
operations. An attacker could possibly use this issue to cause a denial
of service. This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS
and Ubuntu 24.04 LTS. (CVE-2024-25269)

Aldo Ristori discovered that libheif did not correctly handle certain
memory operations. An attacker could possibly use this issue to cause a
denial of service or execute arbitrary code. (CVE-2025-68431)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 25.10
libheif1 1.20.2-1ubuntu0.1

Ubuntu 25.04
libheif1 1.19.7-1ubuntu0.1

Ubuntu 24.04 LTS
libheif1 1.17.6-1ubuntu4.2

Ubuntu 22.04 LTS
libheif1 1.12.0-2ubuntu0.1~esm2
Available with Ubuntu Pro

Ubuntu 20.04 LTS
libheif1 1.6.1-1ubuntu0.1~esm2
Available with Ubuntu Pro

Ubuntu 18.04 LTS
libheif1 1.1.0-2ubuntu0.1~esm2
Available with Ubuntu Pro

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-7952-1
CVE-2024-25269, CVE-2025-68431

Package Information:
https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.1
https://launchpad.net/ubuntu/+source/libheif/1.19.7-1ubuntu0.1
https://launchpad.net/ubuntu/+source/libheif/1.17.6-1ubuntu4.2