Out-of-bounds read in libheif - #VU153984
Published: October 8, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a heap out-of-bounds read in the FFmpeg decoder plugin when processing HEVC image data without the padding required by av_parser_parse2(). A remote attacker can supply an ordinary, valid HEIC file to cause a denial of service.
Exploitation requires the FFmpeg decoder plugin to be enabled and selected. A crash is possible only when memory immediately beyond the allocation is unmapped, such as with certain guard-page allocators. When libde265 is also available, the application must explicitly select the FFmpeg decoder.