Allocation of Resources Without Limits or Throttling in libheif - #VU145239
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in the derived image decode paths when processing crafted grid or overlay images with indirect iden reference chains. A remote attacker can send a specially crafted HEIF or AVIF file to cause a denial of service.
For grid images, triggering the issue requires the consumer to request decoding of the grid image.