Allocation of Resources Without Limits or Throttling in libheif - #VU153986

 

Allocation of Resources Without Limits or Throttling in libheif - #VU153986

Published: October 8, 2026


Vulnerability identifier: #VU153986
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-770
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service through excessive memory allocation.

The vulnerability exists due to incorrect sequence parameter set parsing and unenforced resource limits in the HEVC decoding path when processing image files with sub-layer profiles using the FFmpeg decoder plugin. A remote attacker can supply a crafted file whose sequence parameter set fails parsing and bypasses the size check to cause a denial of service through excessive memory allocation.

Builds using the libde265 decoder plugin are not affected because that plugin independently enforces the image size limit.


Affected software

libheif

Remediation

Install security update from vendor's website.

libheif - update to 1.23.6

External References

Related Security Bulletins