Improper Validation of Specified Quantity in Input in libheif - #VU153981
Published: October 8, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause decoded chroma samples to exceed their declared bit depth.
The vulnerability exists due to improper validation of sample bit widths in unc_decoder_mixed_interleave::processTile() when decoding uncompressed images in mixed interleave mode. A remote attacker can supply a crafted image containing additional sample or alignment padding bits to cause decoded chroma samples to exceed their declared bit depth.
The uncompressed codec must be enabled through WITH_UNCOMPRESSED_CODEC, which is disabled by default. Chroma bit depths other than 8 and 16 are affected. User interaction is required. Excess values reach callers when color conversion is not applied, or survive conversion to RGB when matrix_coefficients is 0 with full range. This issue alone does not cause out-of-bounds memory access within libheif.