Heap-based buffer overflow in libheif - #VU146736
Published: September 2, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to heap-based buffer overflow in svt_encode_sequence_frame() in the SVT-AV1 encoder plugin when encoding an image with an alpha channel at a bit depth greater than 8. A remote attacker can supply a specially crafted image for transcoding to cause a denial of service.
Only builds with the SVT-AV1 encoder plugin enabled are vulnerable, and the issue is triggered on the high-bit-depth alpha-channel code path.