Description
libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1.19.6, Op_RGB24_32_to_YCbCr::convert_colorspace() stores image-plane strides in an integer width that can overflow for extremely large RGB images created through heif_image_create() and heif_image_add_plane(). The resulting wrapped stride causes the conversion loop in libheif/color-conversion/rgb2yuv.cc to compute an invalid input pointer and read beyond the allocated interleaved plane while heif_context_encode_image() performs RGB-to-YCbCr conversion. This can crash the encoding process. This issue is fixed in version 1.19.6.
Published: 2026-09-18
Score: 3.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via segmentation fault
Action: Patch
AI Analysis

Impact

The vulnerability arises when libheif’s conversion routine stores image-plane strides in an integer that can overflow for extremely large RGB images created through heif_image_create() and heif_image_add_plane(). This overflow causes the conversion loop in libheif/color-conversion/rgb2yuv.cc to calculate an invalid input pointer and read beyond the allocated interleaved plane during RGB-to-YCbCr conversion. The result is a crash of the encoding process, which can lead to service disruption or application termination. The weakness is a classic integer overrun (CWE‑125) coupled with potential signed‑to‑unsigned conversion abuse (CWE‑190).

Affected Systems

The flaw affects the libheif library distributed by strukturag. All releases prior to version 1.19.6 are vulnerable. Applications or systems that use these older libheif binaries and process large or malformed HEIF or AVIF images are potentially impacted.

Risk and Exploitability

The CVSS score of 3.7 indicates a moderate severity. The EPSS score of <1% indicates a very low but nonzero exploitation probability, and the flaw is not listed in the CISA KEV catalog, suggesting a lower current exploitation probability. The attack vector is most likely local or remote if an application processes untrusted image files; an attacker could craft a very large image that triggers the overflow during encoding. Because the outcome is a crash rather than arbitrary code execution, the damage is limited to denial of service, but repeated exploitation could degrade availability or trigger downstream failures.

Generated by OpenCVE AI on September 19, 2026 at 17:15 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to libheif version 1.19.6 or later, which applies the stride overflow fix.
  • Prior to upgrading, validate the width and height of images processed by libheif, rejecting those that exceed safe thresholds to avoid triggering the overflow.
  • If a patch cannot be applied immediately, isolate the encoding component in a sandbox or separate process to contain crashes and prevent wider system disruption.

Generated by OpenCVE AI on September 19, 2026 at 17:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Ubuntu USN Ubuntu USN USN-8846-1 libheif vulnerabilities
History

Wed, 23 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Struktur
Struktur libheif
Vendors & Products Struktur
Struktur libheif

Fri, 18 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
Description libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1.19.6, Op_RGB24_32_to_YCbCr::convert_colorspace() stores image-plane strides in an integer width that can overflow for extremely large RGB images created through heif_image_create() and heif_image_add_plane(). The resulting wrapped stride causes the conversion loop in libheif/color-conversion/rgb2yuv.cc to compute an invalid input pointer and read beyond the allocated interleaved plane while heif_context_encode_image() performs RGB-to-YCbCr conversion. This can crash the encoding process. This issue is fixed in version 1.19.6.
Title libheif hOp_RGB24_32_to_YCbCr Memory Access Error / SEGV
Weaknesses CWE-125
CWE-190
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Struktur Libheif
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-22T14:52:30.772Z

Reserved: 2026-09-01T20:05:09.423Z

Link: CVE-2026-84449

cve-icon Vulnrichment

Updated: 2026-09-22T14:52:25.351Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T16:17:12.997

Modified: 2026-09-22T15:17:19.207

Link: CVE-2026-84449

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:15:05Z

Weaknesses