Out-of-bounds write in libheif - #VU145254
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause memory corruption.
The vulnerability exists due to out-of-bounds write in heif_context_add_image_tile() when encoding an ISO/IEC 23001-17 uncompressed tiled image with inconsistent component plane sizes. A remote attacker can supply a specially crafted heif_image tile with component planes larger than its declared dimensions to cause memory corruption.
Only builds with the experimental uncompressed codec enabled are affected.