{"id":"ECHO-ff10-c876-4faa","summary":"Out-of-bounds read in core image-sequence parsing: a malformed HEIF\nsequence with stco.entry_count == 0 and saiz.sample_count \u003e 0 drives\nSampleAuxInfoReader to dereference an empty chunks[0]. This sequence /\nISOBMFF track parsing (SampleAuxInfoReader, Box_saiz/saio/stco,\nTrackBox/MovieBox) was added in v1.20.0. v1.19.8 — the version we\nship — has no track parsing at all, so the vulnerable code is not\npresent (verified: none of those symbols exist in the v1.19.8 source).\n","modified":"2026-09-15T03:33:45.975574153Z","published":"2026-05-26T09:52:21.520Z","withdrawn":"2026-07-15T08:15:03.677Z","upstream":["CVE-2026-41069"],"references":[{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2026-41069"}],"affected":[{"package":{"name":"libheif","ecosystem":"Echo","purl":"pkg:deb/echo/libheif"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.19.8-1"}]}],"database_specific":{"source":"https://advisory.echohq.com/osv/ECHO-ff10-c876-4faa.json"}}],"schema_version":"1.9.0"}