Allocation of Resources Without Limits or Throttling in libheif - #VU147371

 

Allocation of Resources Without Limits or Throttling in libheif - #VU147371

Published: September 8, 2026


Vulnerability identifier: #VU147371
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-770
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper enforcement of resource limits in Box_iinf::parse and Box::read_children when parsing an iinf box with a declared item count. A remote attacker can submit a specially crafted HEIF file to cause a denial of service.

Processing an excessive number of items can consume substantial CPU time and heap memory before image decoding.


Affected software

libheif

Remediation

Install security update from vendor's website.

libheif - update to 1.23.4

External References

Related Security Bulletins