SB2026100861 - Multiple vulnerabilities in libheif



SB2026100861 - Multiple vulnerabilities in libheif

Published: October 8, 2026

Security Bulletin ID SB2026100861
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 7
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Medium 57% Low 43%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 7 vulnerabilities.


1) Incomplete Filtering of Special Elements (CVE-ID: N/A)

CWE-ID: CWE-791 - Incomplete Filtering of Special Elements

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass pre-decode resource-limit checks and pass pathological JPEG 2000 geometry to the external decoder.

The vulnerability exists due to incomplete filtering of absolute image coordinates in openjpeg_decode_next_image2() in libheif/plugins/decoder_openjpeg.cc when processing JPEG 2000 image headers. A remote attacker can supply a crafted J2KI HEIF file containing extremely large absolute coordinates but a small canvas span to bypass pre-decode resource-limit checks and pass pathological JPEG 2000 geometry to the external decoder.

The OpenJPEG decoder must be enabled. The issue is reproducible with default global security limits. Downstream memory-safety consequences depend on the OpenJPEG dependency.


2) Out-of-bounds read (CVE-ID: N/A)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to an out-of-bounds read in unc_encoder_rgb_pixel_interleave when encoding an image with a separate alpha plane attached to an interleaved chroma format that carries no alpha. A local user can control image construction parameters through the public API and invoke uncompressed encoding with this inconsistent configuration to cause a denial of service.

Builds with NDEBUG defined perform a four-byte heap read beyond the component identifier array; assertion-enabled builds abort instead. A malicious image file alone cannot trigger this condition through a normal decode-to-encode pipeline.


3) Use-after-free (CVE-ID: N/A)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to a heap use-after-free and double free caused by shallow copying ImageDescription::m_tai_timestamp in ImageItem::encode_to_bitstream_and_boxes() when re-encoding images with TAI timestamp metadata. A remote attacker can supply a crafted HEIF file containing an itai property to a service that decodes and re-encodes images to cause a denial of service.

The issue is also reachable through normal public API use by calling heif_image_set_tai_timestamp() followed by heif_context_encode_image(). No non-default configuration is required.


4) Allocation of Resources Without Limits or Throttling (CVE-ID: N/A)

CWE-ID: CWE-770 - Allocation of Resources Without Limits or Throttling

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to allocation of resources without enforced memory limits in the JPEG 2000 pclr box parser in libheif/codecs/jpeg2000_boxes.cc when processing palette boxes with zero columns. A remote attacker can submit a specially crafted HEIC/HEIF file containing palette boxes that declare 65,535 entries without palette data to cause a denial of service.

Nested j2kH containers permit repeated palette allocations within the default child-box and nesting limits.


5) Out-of-bounds read (CVE-ID: N/A)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information and cause a denial of service.

The vulnerability exists due to a heap out-of-bounds read in libheif's Op_flatten_alpha_plane::convert_colorspace function when decoding uncompressed images with mismatched per-channel bit depths during alpha compositing. A remote attacker can trick a victim into opening a specially crafted unci image to disclose sensitive information and cause a denial of service.

The uncompressed codec must be enabled at build time and is disabled by default. Exposure of adjacent heap data depends on the caller rendering, re-encoding, or returning the decoded pixels.


6) Allocation of Resources Without Limits or Throttling (CVE-ID: N/A)

CWE-ID: CWE-770 - Allocation of Resources Without Limits or Throttling

CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass application-configured memory allocation limits.

The vulnerability exists due to failure to enforce caller-configured resource limits in libheif's MINI-box parsing when processing untrusted MINI-format HEIF files. A remote attacker can supply a MINI-format file that exceeds the application's configured memory budget to bypass application-configured memory allocation limits.

Only applications that configure stricter-than-default security limits through heif_context_set_security_limits are affected; applications using the default limits are unaffected. MINI parsing is compiled in unconditionally.


7) Resource exhaustion (CVE-ID: N/A)

CWE-ID: CWE-400 - Resource exhaustion

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper enforcement of image size limits in libheif's pre-decode size checks when processing untrusted AVIF images. A remote attacker can submit a crafted AVIF whose in-band AV1 dimensions exceed its declared container dimensions, triggering excessive memory allocation before the image is rejected, to cause a denial of service.

The issue is confirmed with the libaom AV1 decoder backend and default security limits.


Remediation

Install update from vendor's website.