Allocation of Resources Without Limits or Throttling in libheif - #VU145241
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in TiledHeader::set_parameters() when opening a crafted experimental tiled image. A remote attacker can send a specially crafted HEIF or AVIF file to cause a denial of service.
Only builds with the experimental tili feature enabled are vulnerable, and the allocation is triggered at file-open time.