Out-of-bounds read in libheif - #VU153966
Published: October 8, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in unc_encoder_rgb_pixel_interleave when encoding an image with a separate alpha plane attached to an interleaved chroma format that carries no alpha. A local user can control image construction parameters through the public API and invoke uncompressed encoding with this inconsistent configuration to cause a denial of service.
Builds with NDEBUG defined perform a four-byte heap read beyond the component identifier array; assertion-enabled builds abort instead. A malicious image file alone cannot trigger this condition through a normal decode-to-encode pipeline.