Description
libheif is a HEIF and AVIF file format decoder and encoder. From 1.22.0 until 1.23.2, a crafted HEIF, HEIC, or AVIF item graph using nested iden and auxl references can make HeifPixelImage::transfer_channel_from_image_as() append duplicate Alpha planes with different bit depths to m_storage. HeifPixelImage::scale_nearest_neighbor() in libheif/image/pixelimage.cc allocates the destination Alpha plane using the first plane's 8-bit depth, then iterates a later 10-bit or 12-bit Alpha component and writes uint16_t samples into the same 8-bit allocation. The output geometry controls the overflow extent and the encoded sample values control the data written, allowing a remote file processed by heif_decode_image() to cause a heap out-of-bounds write. This issue is fixed in version 1.23.2.
Published: 2026-09-18
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Heap Buffer Overflow potentially leading to arbitrary code execution
Action: Patch Immediately
AI Analysis

Impact

libheif, a HEIF and AVIF decoder/encoder, contains a heap buffer overflow triggered by the function scale_nearest_neighbor(). When a crafted HEIF, HEIC, or AVIF file includes nested iden and auxl references, duplicate Alpha planes with mismatched bit depths can be appended to an image’s internal storage. The scaling routine allocates an 8‑bit Alpha plane but later writes 16‑bit samples from a 10‑bit or 12‑bit Alpha component into the same buffer, causing an out‑of‑bounds write. This memory corruption can lead to application crashes or, if exploited successfully, arbitrary code execution. The vulnerability affects any code that calls heif_decode_image() on untrusted image data.

Affected Systems

The vulnerability applies to strukturag’s libheif library in versions 1.22.0 through 1.23.1. The issue was fixed in release 1.23 releases and lacking the 1.23.2 update are susceptible.

Risk and Exploitability

With a CVSS score of 9.8, the flaw is classified as critical. The EPSS score of 0.00641 (<1%) indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog, but the high CVSS indicates a significant risk. The likely attack vector is a remote or local attacker supplying a maliciously crafted HEIF/AVIF file to a process that uses libheif for decoding. An attacker could trigger a heap overflow that may allow arbitrary code execution if the memory overwrite lands on executable or privileged memory. This makes the vulnerability a serious concern for any system that processes untrusted image data with libheif.

Generated by OpenCVE AI on September 19, 2026 at 17:55 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade libheif to version 1.23.2 or later, the version that contains the fix.
  • If an immediate update is not possible, configure applications that rely on libheif to reject or ignore HEIF/AVIF files, or disable HEIF/AVIF support entirely until the library is patched.
  • Monitor system stability and application logs for unexpected crashes or abnormal memory usage that could indicate exploitation attempts of the legacy libheif.

Generated by OpenCVE AI on September 19, 2026 at 17:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 25 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Critical


Sat, 19 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Struktur
Struktur libheif
Vendors & Products Struktur
Struktur libheif

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description libheif is a HEIF and AVIF file format decoder and encoder. From 1.22.0 until 1.23.2, a crafted HEIF, HEIC, or AVIF item graph using nested iden and auxl references can make HeifPixelImage::transfer_channel_from_image_as() append duplicate Alpha planes with different bit depths to m_storage. HeifPixelImage::scale_nearest_neighbor() in libheif/image/pixelimage.cc allocates the destination Alpha plane using the first plane's 8-bit depth, then iterates a later 10-bit or 12-bit Alpha component and writes uint16_t samples into the same 8-bit allocation. The output geometry controls the overflow extent and the encoded sample values control the data written, allowing a remote file processed by heif_decode_image() to cause a heap out-of-bounds write. This issue is fixed in version 1.23.2.
Title libheif: Heap buffer overflow in `scale_nearest_neighbor()` via duplicate Alpha planes from nested `iden`/`auxl` items
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Struktur Libheif
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-18T16:11:18.781Z

Reserved: 2026-09-01T16:27:58.130Z

Link: CVE-2026-84383

cve-icon Vulnrichment

Updated: 2026-09-18T16:08:21.183Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T16:17:11.707

Modified: 2026-09-18T16:17:11.853

Link: CVE-2026-84383

cve-icon Redhat

Severity : Critical

Publid Date: 2026-09-18T15:55:46Z

Links: CVE-2026-84383 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:15:05Z

Weaknesses