Allocation of Resources Without Limits or Throttling in libheif - #VU153987

 

Allocation of Resources Without Limits or Throttling in libheif - #VU153987

Published: October 8, 2026


Vulnerability identifier: #VU153987
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-770
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service through excessive memory allocation.

The vulnerability exists due to inconsistent NAL unit interpretation and unenforced resource limits in the FFmpeg decoder plugin when processing HEVC NAL units containing embedded start code prefixes. A remote attacker can supply a crafted file that causes FFmpeg to decode NAL units not checked by libheif to cause a denial of service through excessive memory allocation.

Builds using the libde265 decoder plugin are not affected because that plugin independently enforces the image size limit.


Affected software

libheif

Remediation

Install security update from vendor's website.

libheif - update to 1.23.6

External References

Related Security Bulletins