Allocation of Resources Without Limits or Throttling in libheif - #VU145239

 

Allocation of Resources Without Limits or Throttling in libheif - #VU145239

Published: August 25, 2026


Vulnerability identifier: #VU145239
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-770
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to allocation of resources without limits or throttling in the derived image decode paths when processing crafted grid or overlay images with indirect iden reference chains. A remote attacker can send a specially crafted HEIF or AVIF file to cause a denial of service.

For grid images, triggering the issue requires the consumer to request decoding of the grid image.


Affected software

libheif

Remediation

Install security update from vendor's website.

libheif - update to 1.23.2

External References

Related Security Bulletins