Impact
libheif, a HEIF/AVIF decoder, exposes a flaw from version 1.19.0 through 1.23.3 when processing a crafted image that contains a clap property and an ispe width or height exceeding INT32_MAX+1. During tiling calculations the library passes a value that causes the Fraction class constructor’s assertion to trigger in assert‑enabled builds, aborting the process. Release builds bypass the assertion but calculate an unsafe crop geometry, and the tiling API returns dimensions that are outside the normal decode limits, effectively allowing an attacker to induce a denial of service. The impact is limited to an application crash or a malformed geometry restriction, with no direct path to code execution or data exfiltration.
Affected Systems
The affected product is strukturag libheif for all releases from 1.19.0 up to and including 1.23.2. The vulnerability is fixed starting with version 1.23.3, which addresses the overflow and improper geometry handling. Users of any older libheif embedded in their software or binaries must identify the exact version used and plan an upgrade.
Risk and Exploitability
The CVSS score of 4.3 indicates medium severity, and the EPSS score of < 1% indicates a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, suggesting no widespread exploitation reports. Attack vectors are most likely via a forged image file supplied to an application that relies on libheif, which could be local or remote depending on how the image is obtained. The absence of network‑level privileges or privilege escalation requirements further confines the threat to denial of service rather than privilege‑based compromise.
OpenCVE Enrichment
Debian DSA