Description
libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1.23.2, the public heif_region_item_add_region_inline_mask_data() function in libheif/api/libheif/heif_regions.cc accepts mask_data_len without verifying that it equals the byte count required by width and height. A later heif_region_get_mask_image() call derives the read length from the region geometry, so an undersized stored buffer causes heif_region_get_inline_mask_image() to read beyond the heap allocation and copy adjacent bytes into the returned monochrome mask image. This can disclose heap data or crash an application that constructs region metadata through the writer API, while the file-parsing path is not affected because it validates the canonical mask size. This issue is fixed in version 1.23.2.
Published: 2026-09-18
Score: 4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Heap out-of-bounds read that can leak heap data or cause crashes when an application writes HEIF/AVIF inline mask metadata
Action: Apply patch
AI Analysis

Impact

libheif, a HEIF and AVIF decoder and encoder, has a heap out‑of‑bounds read in the inline‑mask API. The public function heif_region_item_add_region_inline_mask_data accepts a mask length parameter without verifying it against the mask’s width and height. Subsequent calls to heif_region_get_mask_image derive the read length from the stored geometry, so an undersized buffer lets the function read beyond its allocated area and copy adjacent heap data into the returned monochrome mask image. This can leak memory contents or crash an application that writes region metadata, while parsing external files is not affected because the library checks mask size during input validation.

Affected Systems

Vendor: strukturag. Product: libheif. Affected versions are all releases prior to 1.23.2. The issue is fixed in release 1.23.2 and later.

Risk and Exploitability

The CVSS score of 4 indicates moderate severity. The EPSS score of <1% indicates a very low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. The flaw is only exploitable when an application uses the writer API to add an inline mask; therefore the attack vector is limited to code that generates HEIF/AVIF output internally, rather than to arbitrary file parsing. An attacker may achieve accidental disclosure of heap data or provoke a crash, but remote code execution appears unlikely. The primary mitigation is upgrading to libheif 1.23.2.

Generated by OpenCVE AI on September 19, 2026 at 17:56 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade libheif to version 1.23.2 or later to eliminate the vulnerability
  • Modify any custom code that calculates mask size to ensure the buffer size equals width multiplied by height
  • Perform regression tests that generate HEIF/AVIF images with inline masks to confirm no crashes or memory disclosures occur

Generated by OpenCVE AI on September 19, 2026 at 17:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6523-1 libheif security update
Ubuntu USN Ubuntu USN USN-8846-1 libheif vulnerabilities
History

Sat, 19 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Struktur
Struktur libheif
Vendors & Products Struktur
Struktur libheif

Fri, 18 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1.23.2, the public heif_region_item_add_region_inline_mask_data() function in libheif/api/libheif/heif_regions.cc accepts mask_data_len without verifying that it equals the byte count required by width and height. A later heif_region_get_mask_image() call derives the read length from the region geometry, so an undersized stored buffer causes heif_region_get_inline_mask_image() to read beyond the heap allocation and copy adjacent bytes into the returned monochrome mask image. This can disclose heap data or crash an application that constructs region metadata through the writer API, while the file-parsing path is not affected because it validates the canonical mask size. This issue is fixed in version 1.23.2.
Title libheif: Heap out-of-bounds read in libheif inline-mask region API (heif_region_item_add_region_inline_mask_data / heif_region_get_mask_image)
Weaknesses CWE-125
CWE-131
References
Metrics cvssV3_1

{'score': 4, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L'}


Subscriptions

Struktur Libheif
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-24T20:58:18.659Z

Reserved: 2026-09-01T20:05:09.423Z

Link: CVE-2026-84448

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-18T16:17:12.840

Modified: 2026-09-24T21:18:55.407

Link: CVE-2026-84448

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:15:05Z

Weaknesses
  • CWE-125

    Out-of-bounds Read

  • CWE-131

    Incorrect Calculation of Buffer Size