libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.0 and earlier, a crafted HEIF or AVIF file containing a clean aperture box can reduce an image dimension to zero and crash or corrupt tiling results when heif_image_handle_get_image_tiling(handle, 1, &tiling) is called. ImageItem::get_heif_image_tiling() returns already transformed dimensions, and process_image_transformations_on_tiling() applies the clean aperture transformation again. The second application passes zero to Box_clap::left_rounded(0), where image_width minus one underflows and constructs Fraction(0xFFFFFFFF, 2). Debug builds reach an assertion and abort, while release builds can return a corrupt crop and zero-width tiling result. The affected implementation spans libheif/image-items/image_item.cc, libheif/context.cc, and libheif/box.cc. This issue is fixed in version 1.23.1.
CVSS Details
- CVSS 3.1 Base Score: 4.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade libheif | Aug 9, 2026 | Aug 9, 2026 |
| Ubuntu | — | Upgrade libheif-plugin-jpegencUpgrade heif-gdk-pixbufUpgrade libheif-plugin-aomdecUpgrade libheif-plugin-ffmpegdecUpgrade libheif-plugin-kvazaarUpgrade libheif-plugin-x265Upgrade libheif-plugin-libde265Upgrade libheif-plugin-svtencUpgrade libheif-plugins-allUpgrade libheif-plugin-dav1dUpgrade libheif-plugin-j2kdecUpgrade libheif-plugin-aomencUpgrade libheif-plugin-rav1eUpgrade libheif1Upgrade libheif-plugin-j2kencUpgrade heif-thumbnailerUpgrade heif-viewUpgrade libheif-plugin-jpegdec | Aug 19, 2026 | Aug 19, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub