libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.0, a crafted HEIF sequence accepted by heif_context_read_from_memory() with the msf1 sequence brand can cause unbounded heap allocation. In libheif/sequences/seq_boxes.cc, Box_stsz::parse() applies max_sequence_frames only to variable-size samples, so fixed-size mode accepts an attacker-controlled sample_count without a bound. In libheif/sequences/track.cc, Track::load() also adds current_sample_idx and samples_per_chunk in 32-bit arithmetic, allowing the consistency check to be bypassed by wraparound. The resulting values reach the Chunk::Chunk() allocation path, which can consume gigabytes of memory and crash or stall the process through memory exhaustion. This issue is fixed in version 1.23.0.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade libheif | Aug 20, 2026 | Aug 18, 2026 |
| Ubuntu | — | Upgrade libheif-plugin-libde265Upgrade libheif-plugin-ffmpegdecUpgrade libheif-plugin-rav1eUpgrade libheif1Upgrade libheif-plugin-aomdecUpgrade heif-viewUpgrade libheif-plugin-j2kdecUpgrade libheif-devUpgrade libheif-plugin-j2kencUpgrade libheif-plugin-aomencUpgrade libheif-plugin-jpegdecUpgrade heif-thumbnailerUpgrade libheif-plugins-allUpgrade libheif-plugin-jpegencUpgrade libheif-plugin-kvazaarUpgrade libheif-plugin-svtencUpgrade libheif-plugin-x265Upgrade libheif-plugin-dav1dUpgrade heif-gdk-pixbufUpgrade libheif-examples | Jul 12, 2026 | Jul 9, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub