Description
libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1.23.2, crafted HEIF sequence timing and edit-list data can make Track::init_sample_timing_table() compute a logical m_num_output_samples value that exceeds the uint32_t counters used by Track_Visual::decode_next_image_sample() and Track::get_next_sample_raw_data(). The resulting comparison can never reach the oversized output count, causing non-terminating decode or raw-sample loops and bypassing max_sequence_frames. The same sequence path repeatedly calls Box_stts::get_sample_duration() and allocates Chunk::m_sample_ranges and Track::m_presentation_timeline outside MemoryHandle accounting, allowing severe CPU and memory exhaustion from a small file. This issue is fixed in version 1.23.2.
Published: 2026-09-18
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

The vulnerability occurs in libheif before version 1.23.2 when a crafted HEIF sequence timing and edit‑list structure causes the Track::init_sample_timing_table() function to compute a logical m_num_output_samples value larger than the 32‑bit counters used during decoding. Because the counter never reaches this oversized value, the decoder enters an infinite loop, bypassing the configured max_sequence_frames guard. Continued iteration of the Box_stts::get_sample_duration() call allocates large Chunk::m_sample_ranges and Track::m_presentation_timeline buffers outside the library’s memory‑management accounting, leading to severe CPU and memory exhaustion even from a small file. The primary effect is a denial‑of‑service condition where an attacker can cause arbitrary resource consumption without tampering with data integrity. The weakness is identified as CWE‑835.

Affected Systems

The flaw affects all releases of the libheif library from strukturag prior to and including version 1.23.1. Any product or application that embeds libheif for HEIF or AVIF decoding – such as image viewers, media players, or file conversion utilities – is vulnerable if it processes untrusted or user‑supplied HEIF files. The affected vendor is strukturag and the product is the libheif decoder/encoder library. Users should check for the presence of libheif in their software stack.

Risk and Exploitability

With a CVSS score of 7.5, this vulnerability is classified as high severity. EPSS score is less than 1%, and it is not listed in the CISA KEV catalog, but the exploit requires only a crafted HEIF file to be parsed. The attack vector is therefore local or remote file processing, depending on how the vulnerable application accepts image input. An attacker can trigger uncontrolled loops that consume CPU cycles and memory, potentially exhausting system resources or causing application crashes. Because the vulnerability does not grant code execution or privilege escalation, the main risk is denial of service rather than direct compromise.

Generated by OpenCVE AI on September 19, 2026 at 17:40 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade libheif to version 1.23.2 or later, ensuring the patched implementation is loaded.
  • If an upgrade cannot be performed immediately, disable or restrict processing of HEIF/AVIF files from untrusted sources, or validate input against strict size and structure criteria before decoding.
  • Apply process‑level resource limits such as ulimit, cgroup memory limits, or Docker container constraints to contain potential memory exhaustion when using libheif.

Generated by OpenCVE AI on September 19, 2026 at 17:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6523-1 libheif security update
Ubuntu USN Ubuntu USN USN-8846-1 libheif vulnerabilities
History

Mon, 21 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Struktur
Struktur libheif
Vendors & Products Struktur
Struktur libheif

Fri, 18 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1.23.2, crafted HEIF sequence timing and edit-list data can make Track::init_sample_timing_table() compute a logical m_num_output_samples value that exceeds the uint32_t counters used by Track_Visual::decode_next_image_sample() and Track::get_next_sample_raw_data(). The resulting comparison can never reach the oversized output count, causing non-terminating decode or raw-sample loops and bypassing max_sequence_frames. The same sequence path repeatedly calls Box_stts::get_sample_duration() and allocates Chunk::m_sample_ranges and Track::m_presentation_timeline outside MemoryHandle accounting, allowing severe CPU and memory exhaustion from a small file. This issue is fixed in version 1.23.2.
Title libheif: Sequence decode timing-table initialization allows non-terminating loops and unbounded memory, bypassing max_sequence_frames
Weaknesses CWE-835
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Struktur Libheif
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-21T20:50:38.007Z

Reserved: 2026-09-01T20:05:09.422Z

Link: CVE-2026-84446

cve-icon Vulnrichment

Updated: 2026-09-18T20:13:17.901Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T16:17:12.513

Modified: 2026-09-21T21:17:13.683

Link: CVE-2026-84446

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:15:05Z

Weaknesses
  • CWE-835

    Loop with Unreachable Exit Condition ('Infinite Loop')