Allocation of Resources Without Limits or Throttling in libheif - #VU153968
Published: October 8, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to allocation of resources without enforced memory limits in the JPEG 2000 pclr box parser in libheif/codecs/jpeg2000_boxes.cc when processing palette boxes with zero columns. A remote attacker can submit a specially crafted HEIC/HEIF file containing palette boxes that declare 65,535 entries without palette data to cause a denial of service.
Nested j2kH containers permit repeated palette allocations within the default child-box and nesting limits.