CVE-2019-11471: Struktur Libheif
High severity, CVSS 8.8. EPSS: 1.8% chance of exploitation in the next 30 days.
libheif 1.4.0 has a use-after-free in heif::HeifContext::Image::set_alpha_channel in heif_context.h because heif_context.cc mishandles references to non-existing alpha images.
Affected products
- Struktur Libheif: version 1.4.0 only
Published 2019-04-23. Last modified 2026-06-17.