Allocation of Resources Without Limits or Throttling in libheif - #VU153986
Published: October 8, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service through excessive memory allocation.
The vulnerability exists due to incorrect sequence parameter set parsing and unenforced resource limits in the HEVC decoding path when processing image files with sub-layer profiles using the FFmpeg decoder plugin. A remote attacker can supply a crafted file whose sequence parameter set fails parsing and bypasses the size check to cause a denial of service through excessive memory allocation.
Builds using the libde265 decoder plugin are not affected because that plugin independently enforces the image size limit.