Impact
libheif implements an uncompressed tile encoder that accepts an independently constructed tile whose component‑plane dimensions need to match the prototype image geometry. The vulnerable routine lacks a size validation check, allowing an oversized component plane to write data beyond the allocated heap buffer. The result is a memory corruption that can be used to crash the application or, if an attacker controls program flow, to execute arbitrary code. The weakness is identified as CWE‑787 – Out‑of‑Bounds Write.
Affected Systems
strukturag’s libheif library in any release before 1.23.2 when the optional WITH_UNCOMPRESSED_CODEC feature is enabled. The patch in version 1.23.2 adds the missing size check, eliminating the vulnerable path.
Risk and Exploitability
The CVSS score of 7.4 categorizes this vulnerability as high severity. The EPSS score is less than 1%, indicating a very low likelihood of exploitation in the wild. It is not listed in the CISA KEV catalog, suggesting that no widespread exploitation has been documented. Exploitation requires a specially crafted HEIF or AVIF file processed by the vulnerable library, so the risk depends on whether the application accepts untrusted input or is exposed to remote file uploads.
OpenCVE Enrichment
Debian DSA