Allocation of Resources Without Limits or Throttling in libheif - #VU153970
Published: October 8, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass application-configured memory allocation limits.
The vulnerability exists due to failure to enforce caller-configured resource limits in libheif's MINI-box parsing when processing untrusted MINI-format HEIF files. A remote attacker can supply a MINI-format file that exceeds the application's configured memory budget to bypass application-configured memory allocation limits.
Only applications that configure stricter-than-default security limits through heif_context_set_security_limits are affected; applications using the default limits are unaffected. MINI parsing is compiled in unconditionally.