Out-of-bounds read in libheif - #VU153975
Published: October 8, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service or disclose memory contents in a consuming application.
nThe vulnerability exists due to an unchecked return value and inconsistent tile bit-depth handling that lead to an out-of-bounds read in grid image decoding when processing tiles with different bit depths. A remote attacker can supply a crafted grid image whose decoded canvas has a lower bit depth than the handle reports to cause a denial of service or disclose memory contents in a consuming application.
nExploitation requires user interaction and an application that decodes without requesting a specific colorspace and chroma format, then reads decoded planes using the bit depth reported by the handle. Parallel tile decoding can cause the canvas bit depth to vary between runs. The single-tile decoding interface also returns tiles without checking their bit depth against the handle.