Impact
A crafted uncompressed HEIF image can trigger an out‑of‑bounds read when the libheif function heif_image_handle_decode_image_tile is called. The bug occurs in unc_decoder::fetch_tile_data on the last advertised tile (4095, 4095) when the offset calculation wraps to zero, bypassing bounds checking and allowing a memcpy of an invalid pointer with an 1‑terabyte length. This results in a process crash and is identified as a CWE‑125 overflow.
Affected Systems
The vulnerability affects the libheif library distributed by strukturag. Versions from 1.19.0 through 1.23.1 are affected; the fix is included in 1.23.1 onward.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity. No EPSS score is available and the issue is not listed in the CISA KEV catalog. Exploitation requires an attacker to supply a malicious HEIF file to an application that decodes the final tile, typically via heif_image_handle_decode_image_tile. Because the fault only causes a crash, the main risk is denial of service rather than code execution, but it can impact services that rely on HEIF processing.
OpenCVE Enrichment
Debian DSA