Out-of-bounds read in libheif - #VU146727

 

Out-of-bounds read in libheif - #VU146727

Published: September 2, 2026


Vulnerability identifier: #VU146727
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to out-of-bounds read in Op_YCbCr420_to_RGB24::convert_colorspace() when decoding an uncompressed HEIF sequence with an odd-height YCbCr 4:2:0 frame through the public sequence decoding API while requesting RGB output. A remote attacker can supply a specially crafted HEIF sequence file to disclose sensitive information.

User interaction is required to process the crafted file, and the issue is reachable only when the uncompressed codec is enabled.


Affected software

libheif

Remediation

Install security update from vendor's website.

libheif - update to 1.23.3

External References

Related Security Bulletins