Use-after-free in libheif - #VU153978
Published: October 8, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose freed memory contents or cause a denial of service.
The vulnerability exists due to use-after-free in the heif-enc raw input loader when handling an image plane allocation failure. A remote attacker can supply a raw image for processing to disclose freed memory contents or cause a denial of service.
Exploitation requires user interaction and memory exhaustion or an exceeded security limit. No input file alone reproduces the issue.