Inefficient Algorithmic Complexity in libheif - #VU153985
Published: October 8, 2026
Vulnerability details
The vulnerability allows a remote attacker to trigger excessive CPU consumption.
The vulnerability exists due to inefficient algorithmic complexity in the unci decoding path, including unc_decoder_pixel_interleave::get_tile_data_sizes, when processing HEIF files with excessively large declared image dimensions. A remote attacker can submit a specially crafted unci-coded HEIF file to trigger excessive CPU consumption.
The issue was reproduced with experimental features enabled and default security limits.