Out-of-bounds read in libheif - #VU145070

 

Out-of-bounds read in libheif - #VU145070

Published: August 25, 2026


Vulnerability identifier: #VU145070
CSH Severity: Medium
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service and disclose sensitive information.

The vulnerability exists due to out-of-bounds read in the YCbCr to RGB color conversion code in libheif when parsing a crafted HEIF file containing an uncompressed YCbCr planar image with an odd component bit depth and decoding it to RGB. A remote attacker can supply a specially crafted HEIF file to cause a denial of service and disclose sensitive information.

User interaction is required to open the crafted file, or the vulnerable application must process it automatically.


Affected software

libheif

Remediation

Install security update from vendor's website.

libheif - update to 1.18.2

External References

Related Security Bulletins