Use-after-free in libheif - #VU153978

 

Use-after-free in libheif - #VU153978

Published: October 8, 2026


Vulnerability identifier: #VU153978
CSH Severity: Low
CVSS v4: 1.8 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-416
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose freed memory contents or cause a denial of service.

The vulnerability exists due to use-after-free in the heif-enc raw input loader when handling an image plane allocation failure. A remote attacker can supply a raw image for processing to disclose freed memory contents or cause a denial of service.

Exploitation requires user interaction and memory exhaustion or an exceeded security limit. No input file alone reproduces the issue.


Affected software

libheif

Remediation

Install security update from vendor's website.

libheif - update to 1.23.6

External References

Related Security Bulletins