Impact
The vulnerability arises when libheif’s conversion routine stores image-plane strides in an integer that can overflow for extremely large RGB images created through heif_image_create() and heif_image_add_plane(). This overflow causes the conversion loop in libheif/color-conversion/rgb2yuv.cc to calculate an invalid input pointer and read beyond the allocated interleaved plane during RGB-to-YCbCr conversion. The result is a crash of the encoding process, which can lead to service disruption or application termination. The weakness is a classic integer overrun (CWE‑125) coupled with potential signed‑to‑unsigned conversion abuse (CWE‑190).
Affected Systems
The flaw affects the libheif library distributed by strukturag. All releases prior to version 1.19.6 are vulnerable. Applications or systems that use these older libheif binaries and process large or malformed HEIF or AVIF images are potentially impacted.
Risk and Exploitability
The CVSS score of 3.7 indicates a moderate severity. The EPSS score of <1% indicates a very low but nonzero exploitation probability, and the flaw is not listed in the CISA KEV catalog, suggesting a lower current exploitation probability. The attack vector is most likely local or remote if an application processes untrusted image files; an attacker could craft a very large image that triggers the overflow during encoding. Because the outcome is a crash rather than arbitrary code execution, the damage is limited to denial of service, but repeated exploitation could degrade availability or trigger downstream failures.
OpenCVE Enrichment
Ubuntu USN