Impact
The vulnerability in libheif allows an attacker to craft HEIF or AVIF files that trigger unbounded memory allocations during Brotli and zlib decompression. Because the decompress_brotli() function lacks an output-size bound and the zlib path only checks a small temporary buffer in a branch not taken by valid streams, an input file can cause the decoder to consume an arbitrary amount of memory and crash the process. This is a classic "insufficient bounds checking" flaw (CWE‑409) that results in a denial‑of‑service condition.
Affected Systems
The flaw affects the libheif library maintained by strukturag, specifically versions 1.19.0 through 1.23.1 inclusive. Systems that use libheif to decode HEIF or AVIF images—such as media players, image editors, and any software that processes these formats—are potentially impacted.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity. The EPSS score of < 1% indicates a very low yet nonzero probability of exploitation, suggesting that while the likelihood is low, the vulnerability remains a valid risk. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit it by providing a malicious HEIF or AVIF file to any component that decodes images using the affected libheif version. Local or remote execution is possible if the target application opens user-controlled files; the attack vector is therefore inferred to be an input‑based local or remote path depending on how the application accesses files.
OpenCVE Enrichment
Debian DSA
Ubuntu USN