libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and below, a crafted 800-byte HEIF sequence file causes an infinite loop in Box_stts::get_sample_duration(), consuming 100% CPU indefinitely with zero progress, leading to DoS. The loop has no iteration limit or timeout and is triggered during file open (parsing) - before any user interaction or image decoding. The process stays alive (no crash, no error logged), making it invisible to crash-based monitoring. This issue has been fixed in version 1.22.0.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade libheif | Jun 18, 2026 | May 19, 2026 |
| Ubuntu | — | Upgrade heif-thumbnailer (Ubuntu Pro)Upgrade libheif-dev (Ubuntu Pro)Upgrade heif-gdk-pixbuf (Ubuntu Pro)Upgrade libheif-plugin-ffmpegdecUpgrade libheif-plugins-allUpgrade libheif1Upgrade libheif-plugin-jpegdecUpgrade libheif-plugin-x265Upgrade libheif-plugin-libde265Upgrade libheif-plugin-jpegencUpgrade libheif-plugin-aomencUpgrade heif-viewUpgrade libheif-devUpgrade libheif-plugin-aomdecUpgrade libheif-plugin-rav1eUpgrade libheif-plugin-j2kdecUpgrade libheif-plugin-kvazaarUpgrade libheif-plugin-svtencUpgrade libheif-plugin-j2kencUpgrade libheif-plugin-dav1dUpgrade heif-gdk-pixbufUpgrade libheif1 (Ubuntu Pro)Upgrade heif-thumbnailer | Jun 21, 2026 | Jun 18, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub