Description
libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1.23.2, when WITH_UNCOMPRESSED_CODEC is enabled, heif_context_add_image_tile() accepts an independently constructed tile whose component-plane dimensions do not match the tile geometry established by the prototype image. ImageItem_uncompressed::add_image_tile() passes that tile directly to unc_encoder::encode_tile(), which lacked the check_component_sizes() gate and sizes its output from the configured tile geometry while copying the tile's actual component-plane dimensions. An oversized component plane can therefore make unc_encoder_component_interleave::encode_tile() copy attacker-controlled data beyond the heap output buffer. This issue is fixed in version 1.23.2.
Published: 2026-09-18
Score: 7.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Memory corruption with potential code execution
Action: Patch Urgently
AI Analysis

Impact

libheif implements an uncompressed tile encoder that accepts an independently constructed tile whose component‑plane dimensions need to match the prototype image geometry. The vulnerable routine lacks a size validation check, allowing an oversized component plane to write data beyond the allocated heap buffer. The result is a memory corruption that can be used to crash the application or, if an attacker controls program flow, to execute arbitrary code. The weakness is identified as CWE‑787 – Out‑of‑Bounds Write.

Affected Systems

strukturag’s libheif library in any release before 1.23.2 when the optional WITH_UNCOMPRESSED_CODEC feature is enabled. The patch in version 1.23.2 adds the missing size check, eliminating the vulnerable path.

Risk and Exploitability

The CVSS score of 7.4 categorizes this vulnerability as high severity. The EPSS score is less than 1%, indicating a very low likelihood of exploitation in the wild. It is not listed in the CISA KEV catalog, suggesting that no widespread exploitation has been documented. Exploitation requires a specially crafted HEIF or AVIF file processed by the vulnerable library, so the risk depends on whether the application accepts untrusted input or is exposed to remote file uploads.

Generated by OpenCVE AI on September 19, 2026 at 17:39 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade libheif to version 1.23.2 or later, which includes the missing size validation.
  • If an upgrade is not viable, disable the WITH_UNCOMPRESSED_CODEC compile option to remove the vulnerable code path.
  • Restrict the processing of HEIF or AVIF files to trusted sources or implement prior validation before passing data to libheif.

Generated by OpenCVE AI on September 19, 2026 at 17:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6523-1 libheif security update
History

Thu, 24 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Struktur
Struktur libheif
Vendors & Products Struktur
Struktur libheif

Fri, 18 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1.23.2, when WITH_UNCOMPRESSED_CODEC is enabled, heif_context_add_image_tile() accepts an independently constructed tile whose component-plane dimensions do not match the tile geometry established by the prototype image. ImageItem_uncompressed::add_image_tile() passes that tile directly to unc_encoder::encode_tile(), which lacked the check_component_sizes() gate and sizes its output from the configured tile geometry while copying the tile's actual component-plane dimensions. An oversized component plane can therefore make unc_encoder_component_interleave::encode_tile() copy attacker-controlled data beyond the heap output buffer. This issue is fixed in version 1.23.2.
Title libheif uncompressed tiled image encoding allows out-of-bounds write
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H'}


Subscriptions

Struktur Libheif
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-22T14:50:28.718Z

Reserved: 2026-09-01T20:05:09.422Z

Link: CVE-2026-84444

cve-icon Vulnrichment

Updated: 2026-09-22T14:50:24.548Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T16:17:12.357

Modified: 2026-09-22T15:17:19.093

Link: CVE-2026-84444

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:15:05Z

Weaknesses