Impact
The flaw allows an attacker to supply a HEIF or AVIF file that contains crafted reference graphs. Because the decoder copies the set of processed image identifiers for every branch and does not enforce a shared operation budget, the same base image can be decoded repeatedly. This results in a large amplification of CPU and memory usage, effectively exhausting system resources. The weakness is classified as a capacity or memory exhaustion error.
Affected Systems
The vulnerability exists in strukturag's libheif library in versions 1.23.1 and earlier. Any application that uses these versions to decode HEIF or AVIF media files is potentially affected.
Risk and Exploitability
The CVSS score of 7.5 indicates a high impact. The EPSS score, reported as < 1%, suggests a very low predicted exploitation likelihood. Nevertheless, the vulnerability can be exploited through a crafted media file that an application processes; based on the description, it is inferred that this file could be delivered locally or over the network if the application accepts user files. The vulnerability is not listed in the CISA KEV catalog. Despite the low EPSS rating, the significant resource amplification makes the risk substantial for any environment that processes many or large image files.
OpenCVE Enrichment
Debian DSA
Ubuntu USN