Memory leak in libheif - #VU147364
Published: September 8, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to missing release of memory after effective lifetime in Track::get_next_sample_raw_data() when processing crafted HEIF sequence files with malformed auxiliary metadata. A remote attacker can supply a crafted file to cause a denial of service.
User interaction is required to process a crafted file.