CVE-2025-29482

Publication date 7 April 2025

Last updated 11 April 2025


Ubuntu priority

Buffer Overflow vulnerability in libheif 1.19.7 allows a local attacker to execute arbitrary code via the SAO (Sample Adaptive Offset) processing of libde265.

Read the notes from the security team

Status

Package Ubuntu Release Status
libheif 24.10 oracular
Vulnerable, fix deferred
24.04 LTS noble
Vulnerable, fix deferred
22.04 LTS jammy
Vulnerable, fix deferred
20.04 LTS focal
Vulnerable, fix deferred
18.04 LTS bionic
Vulnerable, fix deferred

Notes


mdeslaur

This is a stack overflow, so likely limited to a denial of service only because of compiler hardening. does not appear to be a fix available from libheif developers as of 2025-04-11