Description
libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.0 and earlier, a crafted HEIF or AVIF file containing a clean aperture box can reduce an image dimension to zero and crash or corrupt tiling results when heif_image_handle_get_image_tiling(handle, 1, &tiling) is called. ImageItem::get_heif_image_tiling() returns already transformed dimensions, and process_image_transformations_on_tiling() applies the clean aperture transformation again. The second application passes zero to Box_clap::left_rounded(0), where image_width minus one underflows and constructs Fraction(0xFFFFFFFF, 2). Debug builds reach an assertion and abort, while release builds can return a corrupt crop and zero-width tiling result. The affected implementation spans libheif/image-items/image_item.cc, libheif/context.cc, and libheif/box.cc. This issue is fixed in version 1.23.1.
Published: 2026-08-18
Score: 4.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A crafted HEIF or AVIF file that contains a clean aperture box can be processed by libheif to create an image dimension of zero, which triggers an integer underflow in the Fraction constructor when the clean aperture transformation is applied twice. The underflow generates an invalid fraction value that causes a debug build to assert and abort, or a release build to produce a corrupt crop and a zero‑width tiling result. The result is an application crash or delivery of corrupted image data, which effectively constitutes a denial of service.

Affected Systems

The vulnerability is present in the libheif decoder and encoder library from the vendor strukturag for all releases up to and including version 1.23.0. Versions 1.23.1 and newer contain the fix.

Risk and Exploitability

The CVSS score is 4.3, indicating a moderate severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. The flaw is triggered by parsing a maliciously crafted media file, so the attacker needs to supply such a file to an application that uses libheif. Because the issue is local to file processing, exposure is limited to environments that accept external HEIF or AVIF content.

Generated by OpenCVE AI on August 19, 2026 at 00:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade libheif to 1.23.1 or newer.
  • If updates are not immediately possible, restrict or disable HEIF/AVIF file processing for untrusted input.
  • Validate and sanitize media files before passing to libheif, ensuring correct dimensions and avoiding zero values.

Generated by OpenCVE AI on August 19, 2026 at 00:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6417-1 libheif security update
History

Tue, 18 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Description libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.0 and earlier, a crafted HEIF or AVIF file containing a clean aperture box can reduce an image dimension to zero and crash or corrupt tiling results when heif_image_handle_get_image_tiling(handle, 1, &tiling) is called. ImageItem::get_heif_image_tiling() returns already transformed dimensions, and process_image_transformations_on_tiling() applies the clean aperture transformation again. The second application passes zero to Box_clap::left_rounded(0), where image_width minus one underflows and constructs Fraction(0xFFFFFFFF, 2). Debug builds reach an assertion and abort, while release builds can return a corrupt crop and zero-width tiling result. The affected implementation spans libheif/image-items/image_item.cc, libheif/context.cc, and libheif/box.cc. This issue is fixed in version 1.23.1.
Title libheif: Integer underflow in Fraction constructor via double clap transform application
Weaknesses CWE-191
CWE-617
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-08-18T21:19:18.107Z

Reserved: 2026-07-13T18:37:08.488Z

Link: CVE-2026-62289

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-18T22:17:02.720

Modified: 2026-08-18T22:17:02.720

Link: CVE-2026-62289

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-19T01:00:04Z

Weaknesses
  • CWE-191

    Integer Underflow (Wrap or Wraparound)

  • CWE-617

    Reachable Assertion