Out-of-bounds read in libheif - #VU146738
Published: September 2, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in Op_RGB24_32_to_YCbCr::convert_colorspace when encoding an image and converting RGB data to YCbCr. A remote attacker can supply a crafted image with extreme dimensions to trigger a crash and cause a denial of service.
The issue results in a read memory access error and segmentation fault during image encoding.