SB2026093054 - SUSE update for libheif



SB2026093054 - SUSE update for libheif

Published: September 30, 2026

Security Bulletin ID SB2026093054
CSH Severity
High
Patch available
YES
Number of vulnerabilities 8
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 13% Medium 63% Low 25%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 8 vulnerabilities.


1) Heap-based buffer overflow (CVE-ID: CVE-2026-84383)

CWE-ID: CWE-122 - Heap-based Buffer Overflow

CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to a heap-based buffer overflow in HeifPixelImage::scale_nearest_neighbor() when parsing a crafted HEIC, HEIF, or AVIF file with nested iden and auxl item references that create duplicate Alpha planes. A remote attacker can supply a specially crafted file to execute arbitrary code.

Any application using heif_decode_image() is affected, and no special API options or unusual calling patterns are required.


2) Improper handling of highly compressed data (CVE-ID: CVE-2026-84384)

CWE-ID: CWE-409 - Improper Handling of Highly Compressed Data (Data Amplification)

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper handling of highly compressed data in brotli and zlib decompression paths when parsing a crafted HEIF or AVIF file. A remote attacker can supply a decompression bomb to cause a denial of service.

The issue can be triggered during file open, and some variants require the uncompressed codec feature to be enabled.


3) Out-of-bounds write (CVE-ID: CVE-2026-84444)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 8.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause memory corruption.

The vulnerability exists due to out-of-bounds write in heif_context_add_image_tile() when encoding an ISO/IEC 23001-17 uncompressed tiled image with inconsistent component plane sizes. A remote attacker can supply a specially crafted heif_image tile with component planes larger than its declared dimensions to cause memory corruption.

Only builds with the experimental uncompressed codec enabled are affected.


4) Infinite loop (CVE-ID: CVE-2026-84446)

CWE-ID: CWE-835 - Loop with Unreachable Exit Condition ('Infinite Loop')

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to a loop with an unreachable exit condition in the HEIF sequence decode timing-table initialization and sequence decode path when processing a crafted HEIF sequence file. A remote attacker can supply a crafted file with an amplified logical output sample count to cause a denial of service.

The issue can bypass the max_sequence_frames limit because the logical output sample count is not constrained after repeat amplification.


5) Allocation of Resources Without Limits or Throttling (CVE-ID: CVE-2026-84447)

CWE-ID: CWE-770 - Allocation of Resources Without Limits or Throttling

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to allocation of resources without limits or throttling in the derived image decode paths when processing crafted grid or overlay images with indirect iden reference chains. A remote attacker can send a specially crafted HEIF or AVIF file to cause a denial of service.

For grid images, triggering the issue requires the consumer to request decoding of the grid image.


6) Out-of-bounds read (CVE-ID: CVE-2026-84448)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information and cause a denial of service.

The vulnerability exists due to out-of-bounds read in heif_region_get_inline_mask_image() and the inline-mask region writer API when processing caller-supplied inline mask geometry and buffer lengths. A remote attacker can supply an undersized mask buffer with crafted width and height values to disclose sensitive information and cause a denial of service.

The issue is confined to the public writer API and is not reachable through the file-parsing path.


7) Reachable assertion (CVE-ID: CVE-2026-84450)

CWE-ID: CWE-617 - Reachable Assertion

CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to reachable assertion in Fraction::Fraction and Box_clap clap geometry helpers when parsing a crafted AVIF image with a clap property and oversized ispe dimensions. A remote attacker can supply a specially crafted image file to cause a denial of service.

The issue is triggered in assert-enabled builds via the public C API during heif_image_handle_get_image_tiling(), and user interaction is required to open or process the crafted image.


8) Out-of-bounds read (CVE-ID: CVE-2026-84451)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to an out-of-bounds read in unc_decoder::get_compressed_image_data_uncompressed() when decoding an advertised uncompressed image tile from a crafted HEIF file through the public tile API. A remote attacker can provide a crafted HEIF file to cause a denial of service.

User interaction is required to open or process a crafted HEIF file, and the demonstrated trigger requires decoding a high-index advertised tile through heif_image_handle_decode_image_tile().


Remediation

Install update from vendor's website.