CVE-2026-3950 is an out-of-bounds read vulnerability affecting strukturag libheif versions up to 1.21.2, specifically within the Track::load function. This low-severity issue (CVSS 3.1: 3.3) requires local access and low privileges to exploit, potentially leading to a denial of service. While an exploit is reportedly publicly available, it is not listed in common public exploit databases, and there is no evidence of active exploitation. Community and media attention for this vulnerability are currently negligible. Applying the available unofficial patch is the recommended mitigation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Strukturag | Libheif | 1.21.0, 1.21.1, 1.21.2CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.