Signed to Unsigned Conversion Error in libheif - #VU153982
Published: October 8, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause decoded image samples to exceed their declared bit depth.
The vulnerability exists due to an unchecked signed-to-unsigned conversion in the OpenJPEG decoder plugin when decoding JPEG 2000 codestreams with signed components. A remote attacker can supply a crafted codestream containing negative component values to cause decoded image samples to exceed their declared bit depth.
The OpenJPEG decoder must be enabled through WITH_OpenJPEG_DECODER, which is disabled by default. User interaction is required. Excess values reach callers when color conversion is not applied, or survive conversion to RGB when matrix_coefficients is 0 with full range. This issue alone does not cause out-of-bounds memory access within libheif.