Allocation of Resources Without Limits or Throttling in libheif - #VU153987
Published: October 8, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service through excessive memory allocation.
The vulnerability exists due to inconsistent NAL unit interpretation and unenforced resource limits in the FFmpeg decoder plugin when processing HEVC NAL units containing embedded start code prefixes. A remote attacker can supply a crafted file that causes FFmpeg to decode NAL units not checked by libheif to cause a denial of service through excessive memory allocation.
Builds using the libde265 decoder plugin are not affected because that plugin independently enforces the image size limit.