Signed to Unsigned Conversion Error in libheif - #VU153982

 

Signed to Unsigned Conversion Error in libheif - #VU153982

Published: October 8, 2026


Vulnerability identifier: #VU153982
CSH Severity: Low
CVSS v4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-195
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause decoded image samples to exceed their declared bit depth.

The vulnerability exists due to an unchecked signed-to-unsigned conversion in the OpenJPEG decoder plugin when decoding JPEG 2000 codestreams with signed components. A remote attacker can supply a crafted codestream containing negative component values to cause decoded image samples to exceed their declared bit depth.

The OpenJPEG decoder must be enabled through WITH_OpenJPEG_DECODER, which is disabled by default. User interaction is required. Excess values reach callers when color conversion is not applied, or survive conversion to RGB when matrix_coefficients is 0 with full range. This issue alone does not cause out-of-bounds memory access within libheif.


Affected software

libheif

Remediation

Install security update from vendor's website.

libheif - update to 1.23.6

External References

Related Security Bulletins