SB2026100862 - Multiple vulnerabilities in libheif



SB2026100862 - Multiple vulnerabilities in libheif

Published: October 8, 2026

Security Bulletin ID SB2026100862
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 16
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Medium 69% Low 31%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 16 vulnerabilities.


1) Allocation of Resources Without Limits or Throttling (CVE-ID: N/A)

CWE-ID: CWE-770 - Allocation of Resources Without Limits or Throttling

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service through memory exhaustion.

The vulnerability exists due to allocation of resources without enforced limits in the libheif OpenJPEG decoder plugin when parsing the SIZ marker segment of a JPEG 2000 codestream before applying security checks. A remote attacker can supply a specially crafted HEIF file declaring excessive tile and component counts to cause a denial of service through memory exhaustion.

Both still images and image sequences are affected. The allocated memory is freed when header parsing fails, so the allocation is temporary rather than a memory leak. Peak resident memory depends on the allocator.


2) Out-of-bounds read (CVE-ID: N/A)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service or disclose memory contents in a consuming application.

n

The vulnerability exists due to inconsistent bit-depth reporting that leads to an out-of-bounds read in the image-handle bit-depth reporting functions when processing an image whose codec configuration box contradicts its bitstream. A remote attacker can supply a crafted image with a configuration box that reports a higher bit depth than the decoded samples to cause a denial of service or disclose memory contents in a consuming application.

n

Exploitation requires user interaction and an application that decodes without requesting a specific colorspace and chroma format, then reads decoded planes using the bit depth reported by the handle. No out-of-bounds memory access occurs inside libheif. This issue does not depend on optional codecs.


3) Out-of-bounds read (CVE-ID: N/A)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service or disclose memory contents in a consuming application.

n

The vulnerability exists due to an unchecked return value and inconsistent tile bit-depth handling that lead to an out-of-bounds read in grid image decoding when processing tiles with different bit depths. A remote attacker can supply a crafted grid image whose decoded canvas has a lower bit depth than the handle reports to cause a denial of service or disclose memory contents in a consuming application.

n

Exploitation requires user interaction and an application that decodes without requesting a specific colorspace and chroma format, then reads decoded planes using the bit depth reported by the handle. Parallel tile decoding can cause the canvas bit depth to vary between runs. The single-tile decoding interface also returns tiles without checking their bit depth against the handle.


4) Out-of-bounds read (CVE-ID: N/A)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service or disclose memory contents in a consuming application.

n

The vulnerability exists due to inconsistent overlay canvas bit-depth handling that leads to an out-of-bounds read in overlay image decoding when composing an overlay whose first input image has more than 8 bits per sample. A remote attacker can supply an overlay image whose handle reports more than 8 bits per sample but whose decoded canvas contains 8-bit samples to cause a denial of service or disclose memory contents in a consuming application.

n

Exploitation requires user interaction and an application that decodes without requesting a specific colorspace and chroma format, then reads decoded planes using the bit depth reported by the handle. The mismatch also occurs with ordinary overlays created using heif_context_add_overlay_image(); malformed file contents are not required.


5) Use-after-free (CVE-ID: N/A)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 1.8 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose freed memory contents or cause a denial of service.

The vulnerability exists due to use-after-free in the heif-enc WebP input loader when handling an image plane allocation failure. A remote attacker can supply a WebP image for processing to disclose freed memory contents or cause a denial of service.

Exploitation requires user interaction and memory exhaustion or an exceeded security limit. No input file alone reproduces the issue.


6) Use-after-free (CVE-ID: N/A)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 1.8 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose freed memory contents or cause a denial of service.

The vulnerability exists due to use-after-free in the heif-enc raw input loader when handling an image plane allocation failure. A remote attacker can supply a raw image for processing to disclose freed memory contents or cause a denial of service.

Exploitation requires user interaction and memory exhaustion or an exceeded security limit. No input file alone reproduces the issue.


7) Reachable assertion (CVE-ID: N/A)

CWE-ID: CWE-617 - Reachable Assertion

CVSSv4: 5.6 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to a reachable assertion in ImageItem_Grid::decode_and_paste_tile_image() in libheif/image-items/grid.cc when decoding a grid image whose tiles have an alpha plane with more than 16 bits per sample. A remote attacker can supply a specially crafted image file to cause a denial of service.

Exploitation requires user interaction and a build with assertions enabled and the uncompressed codec enabled through WITH_UNCOMPRESSED_CODEC. The uncompressed codec is disabled in the default build configuration.


8) Incorrect Bitwise Shift of Integer (CVE-ID: N/A)

CWE-ID: CWE-1335 - Incorrect Bitwise Shift of Integer

CVSSv4: 5.6 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to trigger undefined behavior during image decoding.

The vulnerability exists due to an incorrect bitwise shift of an integer in ImageItem_Grid::decode_and_paste_tile_image() in libheif/image-items/grid.cc when computing the opaque alpha value for a grid image tile with a 64-bit alpha component. A remote attacker can supply a specially crafted image file that causes a shift by 64 bits to trigger undefined behavior during image decoding.

Exploitation requires user interaction and a build without assertions and with the uncompressed codec enabled through WITH_UNCOMPRESSED_CODEC. The uncompressed codec is disabled in the default build configuration.


9) Improper Validation of Specified Quantity in Input (CVE-ID: N/A)

CWE-ID: CWE-1284 - Improper Validation of Specified Quantity in Input

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause decoded chroma samples to exceed their declared bit depth.

The vulnerability exists due to improper validation of sample bit widths in unc_decoder_mixed_interleave::processTile() when decoding uncompressed images in mixed interleave mode. A remote attacker can supply a crafted image containing additional sample or alignment padding bits to cause decoded chroma samples to exceed their declared bit depth.

The uncompressed codec must be enabled through WITH_UNCOMPRESSED_CODEC, which is disabled by default. Chroma bit depths other than 8 and 16 are affected. User interaction is required. Excess values reach callers when color conversion is not applied, or survive conversion to RGB when matrix_coefficients is 0 with full range. This issue alone does not cause out-of-bounds memory access within libheif.


10) Signed to Unsigned Conversion Error (CVE-ID: N/A)

CWE-ID: CWE-195 - Signed to Unsigned Conversion Error

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause decoded image samples to exceed their declared bit depth.

The vulnerability exists due to an unchecked signed-to-unsigned conversion in the OpenJPEG decoder plugin when decoding JPEG 2000 codestreams with signed components. A remote attacker can supply a crafted codestream containing negative component values to cause decoded image samples to exceed their declared bit depth.

The OpenJPEG decoder must be enabled through WITH_OpenJPEG_DECODER, which is disabled by default. User interaction is required. Excess values reach callers when color conversion is not applied, or survive conversion to RGB when matrix_coefficients is 0 with full range. This issue alone does not cause out-of-bounds memory access within libheif.


11) Out-of-bounds read (CVE-ID: N/A)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service and potentially disclose limited process memory.

n

The vulnerability exists due to an out-of-bounds read in libsharpyuv gamma table lookups invoked by libheif's sharp-yuv color conversion operator when converting 10-bit or 12-bit RGB images to YCbCr 4:2:0 without validating sample values against the declared bit depth. A remote attacker can trick a victim into processing a crafted image containing out-of-range samples to cause a denial of service and potentially disclose limited process memory.

n

Only builds with libsharpyuv support enabled through WITH_LIBSHARPYUV are affected. Crafted files can reach the vulnerable conversion through the mixed-interleave unci decoder or the OpenJPEG decoder plugin for JPEG 2000 images with signed components when matrix_coefficients is 0 and full_range_flag is 1.


12) Out-of-bounds read (CVE-ID: N/A)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to a heap out-of-bounds read in the FFmpeg decoder plugin when processing HEVC image data without the padding required by av_parser_parse2(). A remote attacker can supply an ordinary, valid HEIC file to cause a denial of service.

Exploitation requires the FFmpeg decoder plugin to be enabled and selected. A crash is possible only when memory immediately beyond the allocation is unmapped, such as with certain guard-page allocators. When libde265 is also available, the application must explicitly select the FFmpeg decoder.


13) Inefficient Algorithmic Complexity (CVE-ID: N/A)

CWE-ID: CWE-407 - Inefficient Algorithmic Complexity

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to trigger excessive CPU consumption.

The vulnerability exists due to inefficient algorithmic complexity in the unci decoding path, including unc_decoder_pixel_interleave::get_tile_data_sizes, when processing HEIF files with excessively large declared image dimensions. A remote attacker can submit a specially crafted unci-coded HEIF file to trigger excessive CPU consumption.

The issue was reproduced with experimental features enabled and default security limits.


14) Allocation of Resources Without Limits or Throttling (CVE-ID: N/A)

CWE-ID: CWE-770 - Allocation of Resources Without Limits or Throttling

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service through excessive memory allocation.

The vulnerability exists due to incorrect sequence parameter set parsing and unenforced resource limits in the HEVC decoding path when processing image files with sub-layer profiles using the FFmpeg decoder plugin. A remote attacker can supply a crafted file whose sequence parameter set fails parsing and bypasses the size check to cause a denial of service through excessive memory allocation.

Builds using the libde265 decoder plugin are not affected because that plugin independently enforces the image size limit.


15) Allocation of Resources Without Limits or Throttling (CVE-ID: N/A)

CWE-ID: CWE-770 - Allocation of Resources Without Limits or Throttling

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service through excessive memory allocation.

The vulnerability exists due to inconsistent NAL unit interpretation and unenforced resource limits in the FFmpeg decoder plugin when processing HEVC NAL units containing embedded start code prefixes. A remote attacker can supply a crafted file that causes FFmpeg to decode NAL units not checked by libheif to cause a denial of service through excessive memory allocation.

Builds using the libde265 decoder plugin are not affected because that plugin independently enforces the image size limit.


16) Asymmetric Resource Consumption (Amplification) (CVE-ID: N/A)

CWE-ID: CWE-405 - Asymmetric Resource Consumption (Amplification)

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service through CPU exhaustion.

The vulnerability exists due to repeated decompression of the entire image item for each tile in unc_decoder::get_compressed_image_data_uncompressed() when decoding a generically compressed unci item with a cmpC box and no icef unit table. A remote attacker can submit a specially crafted HEIF file to an unattended image-processing pipeline to cause a denial of service through CPU exhaustion.

Exploitation requires a build with WITH_UNCOMPRESSED_CODEC=ON and zlib or brotli available at configure time.


Remediation

Install update from vendor's website.