Integer overflow in libheif - #VU128023

 

Integer overflow in libheif - #VU128023

Published: April 27, 2026


Vulnerability identifier: #VU128023
CSH Severity: Low
CVSS v4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-190
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to overwrite image data.

The vulnerability exists due to integer overflow in readTiledSeparate() in heifio/decoder_tiff.cc when decoding crafted tiled TIFF images. A remote attacker can trick the victim into processing a specially crafted TIFF image to overwrite image data.

User interaction is required to process the crafted image.


Affected software

libheif

Remediation

Install security update from vendor's repository.


External References

Related Security Bulletins