Description
libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.1 and earlier, crafted grid, iovl, and iden reference graphs can repeatedly decode the same base image because processed_ids is copied per branch and ImageItem::decode_image() has no shared operation budget. This vulnerability is fixed in 1.23.2.
Published: 2026-09-18
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via CPU/memory amplification
Action: Upgrade
AI Analysis

Impact

The flaw allows an attacker to supply a HEIF or AVIF file that contains crafted reference graphs. Because the decoder copies the set of processed image identifiers for every branch and does not enforce a shared operation budget, the same base image can be decoded repeatedly. This results in a large amplification of CPU and memory usage, effectively exhausting system resources. The weakness is classified as a capacity or memory exhaustion error.

Affected Systems

The vulnerability exists in strukturag's libheif library in versions 1.23.1 and earlier. Any application that uses these versions to decode HEIF or AVIF media files is potentially affected.

Risk and Exploitability

The CVSS score of 7.5 indicates a high impact. The EPSS score, reported as < 1%, suggests a very low predicted exploitation likelihood. Nevertheless, the vulnerability can be exploited through a crafted media file that an application processes; based on the description, it is inferred that this file could be delivered locally or over the network if the application accepts user files. The vulnerability is not listed in the CISA KEV catalog. Despite the low EPSS rating, the significant resource amplification makes the risk substantial for any environment that processes many or large image files.

Generated by OpenCVE AI on September 19, 2026 at 17:38 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update libheif to version 1.23.2 or later.
  • If the upgrade cannot be applied immediately, isolate the image decoding process in a sandboxed environment or enforce strict size limits on input files.
  • Apply application‑level validation to reject or restrict HEIF/AVIF files that contain grid, iovl, or iden reference chains before they reach the decoder.

Generated by OpenCVE AI on September 19, 2026 at 17:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6523-1 libheif security update
Ubuntu USN Ubuntu USN USN-8846-1 libheif vulnerabilities
History

Sat, 19 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Struktur
Struktur libheif
Vendors & Products Struktur
Struktur libheif

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
Description libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.1 and earlier, crafted grid, iovl, and iden reference graphs can repeatedly decode the same base image because processed_ids is copied per branch and ImageItem::decode_image() has no shared operation budget. This vulnerability is fixed in 1.23.2.
Title libheif: Derived-image indirect reference chains and tiled offsets bypass decode caching and MemoryHandle limits, causing CPU/memory amplification DoS
Weaknesses CWE-770
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Struktur Libheif
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-18T17:29:58.718Z

Reserved: 2026-09-01T20:05:09.422Z

Link: CVE-2026-84447

cve-icon Vulnrichment

Updated: 2026-09-18T17:29:51.468Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T16:17:12.677

Modified: 2026-09-18T18:17:17.017

Link: CVE-2026-84447

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:15:05Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling