Infinite loop in libheif - CVE-2026-32739
Published: May 20, 2026
libheif
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to loop with unreachable exit condition in Box_stts::get_sample_duration() when parsing a crafted HEIF sequence file during file open. A remote attacker can send a specially crafted file to cause a denial of service.
User interaction is required to open the crafted file.