Impact
libheif is a decoder and encoder for HEIF and AVIF image formats. In versions 1.19.0 through 1.21.2 a heap out‑of‑bounds read occurs in ImageItem_Grid::decode_grid_tile when an irot value causes a tile‑coordinate underflow. A malicious HEIF or AVIF file containing such an underflowing coordinate can make the library read beyond allocated memory, potentially exposing confidential data from the process heap, which may lead to information disclosure. Version 1.22.0 resolves the problem.
Affected Systems
The affected product is strukturag:libheif. Versions 1.19.0 through 1.21.2 are vulnerable, and the issue is fixed in libheif 1.22.0 and later.
Risk and Exploitability
The CVSS score is 7.1, indicating a high severity. The EPSS score is below 1%, suggesting a low probability of widespread exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires an attacker to supply a crafted HEIF/AVIF file to an application that uses the vulnerable libheif build. The likely attack vector is remote, via any component that decodes untrusted image data, or local if the attacker can influence image input to the host system. The absence of a public exploit but the presence of a low EPSS indicates that defensive measures remain prudent.
OpenCVE Enrichment
Debian DSA
Ubuntu USN