Integer underflow in libheif - #VU135515
Published: June 26, 2026
libheif
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to integer underflow in the Fraction constructor when processing a crafted HEIF/AVIF file through the tiling API with process_image_transformations=1. A remote attacker can supply a specially crafted file to cause a denial of service.
User interaction is required to open the crafted file, or the issue can be triggered server-side when uploaded content is processed automatically.