SB2026092969 - Ubuntu update for libheif



SB2026092969 - Ubuntu update for libheif

Published: September 29, 2026

Security Bulletin ID SB2026092969
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 5
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Medium 60% Low 40%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 5 vulnerabilities.


1) Improper handling of highly compressed data (CVE-ID: CVE-2026-84384)

CWE-ID: CWE-409 - Improper Handling of Highly Compressed Data (Data Amplification)

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper handling of highly compressed data in brotli and zlib decompression paths when parsing a crafted HEIF or AVIF file. A remote attacker can supply a decompression bomb to cause a denial of service.

The issue can be triggered during file open, and some variants require the uncompressed codec feature to be enabled.


2) Infinite loop (CVE-ID: CVE-2026-84446)

CWE-ID: CWE-835 - Loop with Unreachable Exit Condition ('Infinite Loop')

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to a loop with an unreachable exit condition in the HEIF sequence decode timing-table initialization and sequence decode path when processing a crafted HEIF sequence file. A remote attacker can supply a crafted file with an amplified logical output sample count to cause a denial of service.

The issue can bypass the max_sequence_frames limit because the logical output sample count is not constrained after repeat amplification.


3) Allocation of Resources Without Limits or Throttling (CVE-ID: CVE-2026-84447)

CWE-ID: CWE-770 - Allocation of Resources Without Limits or Throttling

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to allocation of resources without limits or throttling in the derived image decode paths when processing crafted grid or overlay images with indirect iden reference chains. A remote attacker can send a specially crafted HEIF or AVIF file to cause a denial of service.

For grid images, triggering the issue requires the consumer to request decoding of the grid image.


4) Out-of-bounds read (CVE-ID: CVE-2026-84448)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information and cause a denial of service.

The vulnerability exists due to out-of-bounds read in heif_region_get_inline_mask_image() and the inline-mask region writer API when processing caller-supplied inline mask geometry and buffer lengths. A remote attacker can supply an undersized mask buffer with crafted width and height values to disclose sensitive information and cause a denial of service.

The issue is confined to the public writer API and is not reachable through the file-parsing path.


5) Out-of-bounds read (CVE-ID: CVE-2026-84449)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to an out-of-bounds read in Op_RGB24_32_to_YCbCr::convert_colorspace when encoding an image and converting RGB data to YCbCr. A remote attacker can supply a crafted image with extreme dimensions to trigger a crash and cause a denial of service.

The issue results in a read memory access error and segmentation fault during image encoding.


Remediation

Install update from vendor's website.