Out-of-bounds read in libheif - #VU153969
Published: October 8, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information and cause a denial of service.
The vulnerability exists due to a heap out-of-bounds read in libheif's Op_flatten_alpha_plane::convert_colorspace function when decoding uncompressed images with mismatched per-channel bit depths during alpha compositing. A remote attacker can trick a victim into opening a specially crafted unci image to disclose sensitive information and cause a denial of service.
The uncompressed codec must be enabled at build time and is disabled by default. Exposure of adjacent heap data depends on the caller rendering, re-encoding, or returning the decoded pixels.