Out-of-bounds read in libheif - #VU145070
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service and disclose sensitive information.
The vulnerability exists due to out-of-bounds read in the YCbCr to RGB color conversion code in libheif when parsing a crafted HEIF file containing an uncompressed YCbCr planar image with an odd component bit depth and decoding it to RGB. A remote attacker can supply a specially crafted HEIF file to cause a denial of service and disclose sensitive information.
User interaction is required to open the crafted file, or the vulnerable application must process it automatically.