Impact
libheif, a HEIF and AVIF decoder and encoder, has a heap out‑of‑bounds read in the inline‑mask API. The public function heif_region_item_add_region_inline_mask_data accepts a mask length parameter without verifying it against the mask’s width and height. Subsequent calls to heif_region_get_mask_image derive the read length from the stored geometry, so an undersized buffer lets the function read beyond its allocated area and copy adjacent heap data into the returned monochrome mask image. This can leak memory contents or crash an application that writes region metadata, while parsing external files is not affected because the library checks mask size during input validation.
Affected Systems
Vendor: strukturag. Product: libheif. Affected versions are all releases prior to 1.23.2. The issue is fixed in release 1.23.2 and later.
Risk and Exploitability
The CVSS score of 4 indicates moderate severity. The EPSS score of <1% indicates a very low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. The flaw is only exploitable when an application uses the writer API to add an inline mask; therefore the attack vector is limited to code that generates HEIF/AVIF output internally, rather than to arbitrary file parsing. An attacker may achieve accidental disclosure of heap data or provoke a crash, but remote code execution appears unlikely. The primary mitigation is upgrading to libheif 1.23.2.
OpenCVE Enrichment
Debian DSA
Ubuntu USN