Out-of-bounds read in libheif - #VU153976
Published: October 8, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service or disclose memory contents in a consuming application.
nThe vulnerability exists due to inconsistent overlay canvas bit-depth handling that leads to an out-of-bounds read in overlay image decoding when composing an overlay whose first input image has more than 8 bits per sample. A remote attacker can supply an overlay image whose handle reports more than 8 bits per sample but whose decoded canvas contains 8-bit samples to cause a denial of service or disclose memory contents in a consuming application.
nExploitation requires user interaction and an application that decodes without requesting a specific colorspace and chroma format, then reads decoded planes using the bit depth reported by the handle. The mismatch also occurs with ordinary overlays created using heif_context_add_overlay_image(); malformed file contents are not required.