Use-after-free in libheif - #VU153977

 

Use-after-free in libheif - #VU153977

Published: October 8, 2026


Vulnerability identifier: #VU153977
CSH Severity: Low
CVSS v4: 1.8 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-416
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose freed memory contents or cause a denial of service.

The vulnerability exists due to use-after-free in the heif-enc WebP input loader when handling an image plane allocation failure. A remote attacker can supply a WebP image for processing to disclose freed memory contents or cause a denial of service.

Exploitation requires user interaction and memory exhaustion or an exceeded security limit. No input file alone reproduces the issue.


Affected software

libheif

Remediation

Install security update from vendor's website.

libheif - update to 1.23.6

External References

Related Security Bulletins