Uncaught Exception in libheif - #VU147365
Published: September 8, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an uncaught exception in heif_track_get_next_raw_sequence_sample() when processing a crafted HEIF sequence file containing an attacker-sized sample under memory pressure. A remote attacker can supply a crafted file to cause a denial of service.
User interaction is required to process a crafted file, and exploitation requires an allocation failure.