Impact
The vulnerability occurs in libheif before version 1.23.2 when a crafted HEIF sequence timing and edit‑list structure causes the Track::init_sample_timing_table() function to compute a logical m_num_output_samples value larger than the 32‑bit counters used during decoding. Because the counter never reaches this oversized value, the decoder enters an infinite loop, bypassing the configured max_sequence_frames guard. Continued iteration of the Box_stts::get_sample_duration() call allocates large Chunk::m_sample_ranges and Track::m_presentation_timeline buffers outside the library’s memory‑management accounting, leading to severe CPU and memory exhaustion even from a small file. The primary effect is a denial‑of‑service condition where an attacker can cause arbitrary resource consumption without tampering with data integrity. The weakness is identified as CWE‑835.
Affected Systems
The flaw affects all releases of the libheif library from strukturag prior to and including version 1.23.1. Any product or application that embeds libheif for HEIF or AVIF decoding – such as image viewers, media players, or file conversion utilities – is vulnerable if it processes untrusted or user‑supplied HEIF files. The affected vendor is strukturag and the product is the libheif decoder/encoder library. Users should check for the presence of libheif in their software stack.
Risk and Exploitability
With a CVSS score of 7.5, this vulnerability is classified as high severity. EPSS score is less than 1%, and it is not listed in the CISA KEV catalog, but the exploit requires only a crafted HEIF file to be parsed. The attack vector is therefore local or remote file processing, depending on how the vulnerable application accepts image input. An attacker can trigger uncontrolled loops that consume CPU cycles and memory, potentially exhausting system resources or causing application crashes. Because the vulnerability does not grant code execution or privilege escalation, the main risk is denial of service rather than direct compromise.
OpenCVE Enrichment
Debian DSA
Ubuntu USN