Impact
libheif, a HEIF and AVIF decoder/encoder, contains a heap buffer overflow triggered by the function scale_nearest_neighbor(). When a crafted HEIF, HEIC, or AVIF file includes nested iden and auxl references, duplicate Alpha planes with mismatched bit depths can be appended to an image’s internal storage. The scaling routine allocates an 8‑bit Alpha plane but later writes 16‑bit samples from a 10‑bit or 12‑bit Alpha component into the same buffer, causing an out‑of‑bounds write. This memory corruption can lead to application crashes or, if exploited successfully, arbitrary code execution. The vulnerability affects any code that calls heif_decode_image() on untrusted image data.
Affected Systems
The vulnerability applies to strukturag’s libheif library in versions 1.22.0 through 1.23.1. The issue was fixed in release 1.23 releases and lacking the 1.23.2 update are susceptible.
Risk and Exploitability
With a CVSS score of 9.8, the flaw is classified as critical. The EPSS score of 0.00641 (<1%) indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog, but the high CVSS indicates a significant risk. The likely attack vector is a remote or local attacker supplying a maliciously crafted HEIF/AVIF file to a process that uses libheif for decoding. An attacker could trigger a heap overflow that may allow arbitrary code execution if the memory overwrite lands on executable or privileged memory. This makes the vulnerability a serious concern for any system that processes untrusted image data with libheif.
OpenCVE Enrichment