libheif vulnerabilities could lead to denial of service in Ubuntu 25.10

Published:

spot_img

Security Advisory: libheif Vulnerabilities in Ubuntu 25.10

Recent security findings have identified two significant vulnerabilities in the libheif library, which could lead to denial of service (DoS) conditions in Ubuntu 25.10. These vulnerabilities are detailed in the Ubuntu Security Notice USN-8649-1.

Identified Vulnerabilities

The first vulnerability, documented as CVE-2026-62289, involves an integer underflow in the Fraction constructor when a clap transform is applied twice. This flaw could potentially allow an attacker to exploit the library, leading to a crash and subsequent denial of service.

The second vulnerability, identified as CVE-2026-62292, pertains to an out-of-bounds read during uncompressed tile range slicing. This issue is specific to Ubuntu 25.10 and could similarly result in a crash of the libheif library, causing a denial of service.

Recommended Actions

Organizations and system administrators using Ubuntu 25.10 should take immediate action to mitigate these vulnerabilities. It is advisable to monitor for updates from Ubuntu and apply any available patches as soon as they are released. Regularly reviewing security advisories and implementing recommended security practices can help safeguard systems against potential exploitation.

Readers can also explore current and upcoming editions through the Cyber Warriors Middle East Resources section.

spot_img

Related articles

Recent articles

StopAndProtect Operation Exploits Thousands of Hacked WordPress Sites for Data Theft

Research by: Jaromír Hořejší (@JaromirHorejsi) StopAndProtect Operation: A New Threat Landscape The StopAndProtect operation has emerged as a significant threat, exploiting thousands of compromised WordPress sites...

OpenAI Focuses on AI-Native Growth in UAE with Local Data Residency Initiatives

OpenAI Targets AI-Native Growth in UAE with Local Data Residency Initiatives Dubai — OpenAI is intensifying its focus on the UAE as it seeks to...

Critical macOS, SharePoint, vCenter, and Microsoft IKE Vulnerabilities Under Active Exploitation, CISA Warns

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has identified four critical vulnerabilities that are currently being exploited in the wild. These vulnerabilities have...

StopAndProtect Campaign Exploits Nearly 2,000 Hacked WordPress Sites for Malware Distribution and Data Theft

Cybersecurity researchers have identified a significant cybercrime operation known as StopAndProtect, which exploits nearly 2,000 hacked WordPress websites to distribute malware and facilitate data...