Allocation of Resources Without Limits or Throttling in libheif - #VU153972
Published: October 8, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service through memory exhaustion.
The vulnerability exists due to allocation of resources without enforced limits in the libheif OpenJPEG decoder plugin when parsing the SIZ marker segment of a JPEG 2000 codestream before applying security checks. A remote attacker can supply a specially crafted HEIF file declaring excessive tile and component counts to cause a denial of service through memory exhaustion.
Both still images and image sequences are affected. The allocated memory is freed when header parsing fails, so the allocation is temporary rather than a memory leak. Peak resident memory depends on the allocator.