Description
libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.3, a crafted image item containing a clap property and an ispe width or height greater than INT32_MAX + 1 can reach crop calculations through heif_image_handle_get_image_tiling(). Box_clap::left_rounded() or Box_clap::top_rounded() passes the image dimension minus one to Fraction::Fraction(), whose uint32_t constructor uses an assertion as input validation, causing assert-enabled builds to abort. Release builds can instead compute invalid crop geometry, and the tiling API returns dimensions that the normal decode security limits reject. This issue is fixed in version 1.23.3.
Published: 2026-09-18
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service (library crash or invalid geometry)
Action: Immediate Patch
AI Analysis

Impact

libheif, a HEIF/AVIF decoder, exposes a flaw from version 1.19.0 through 1.23.3 when processing a crafted image that contains a clap property and an ispe width or height exceeding INT32_MAX+1. During tiling calculations the library passes a value that causes the Fraction class constructor’s assertion to trigger in assert‑enabled builds, aborting the process. Release builds bypass the assertion but calculate an unsafe crop geometry, and the tiling API returns dimensions that are outside the normal decode limits, effectively allowing an attacker to induce a denial of service. The impact is limited to an application crash or a malformed geometry restriction, with no direct path to code execution or data exfiltration.

Affected Systems

The affected product is strukturag libheif for all releases from 1.19.0 up to and including 1.23.2. The vulnerability is fixed starting with version 1.23.3, which addresses the overflow and improper geometry handling. Users of any older libheif embedded in their software or binaries must identify the exact version used and plan an upgrade.

Risk and Exploitability

The CVSS score of 4.3 indicates medium severity, and the EPSS score of < 1% indicates a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, suggesting no widespread exploitation reports. Attack vectors are most likely via a forged image file supplied to an application that relies on libheif, which could be local or remote depending on how the image is obtained. The absence of network‑level privileges or privilege escalation requirements further confines the threat to denial of service rather than privilege‑based compromise.

Generated by OpenCVE AI on September 19, 2026 at 17:37 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade libheif to version 1.23.3 or later to obtain the official fix for this overflow and assertion failure.
  • Validate image dimensions before feeding data to libheif, rejecting any image whose clap property or ispe width or height exceeds INT32_MAX to prevent the overflow condition.
  • If an upgrade cannot be applied immediately, isolate libheif usage by running image processing in a sandboxed or separate process to contain any crash or invalid geometry handling.

Generated by OpenCVE AI on September 19, 2026 at 17:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6523-1 libheif security update
History

Mon, 21 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Struktur
Struktur libheif
Vendors & Products Struktur
Struktur libheif

Fri, 18 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
Description libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.3, a crafted image item containing a clap property and an ispe width or height greater than INT32_MAX + 1 can reach crop calculations through heif_image_handle_get_image_tiling(). Box_clap::left_rounded() or Box_clap::top_rounded() passes the image dimension minus one to Fraction::Fraction(), whose uint32_t constructor uses an assertion as input validation, causing assert-enabled builds to abort. Release builds can instead compute invalid crop geometry, and the tiling API returns dimensions that the normal decode security limits reject. This issue is fixed in version 1.23.3.
Title libheif: `clap` + oversized `ispe` aborts on an assert in `Fraction::Fraction` (incomplete fix for CVE-2026-62289)
Weaknesses CWE-617
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L'}


Subscriptions

Struktur Libheif
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-21T20:50:24.867Z

Reserved: 2026-09-01T20:05:09.423Z

Link: CVE-2026-84450

cve-icon Vulnrichment

Updated: 2026-09-18T19:30:31.579Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T16:17:13.160

Modified: 2026-09-21T21:17:13.800

Link: CVE-2026-84450

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:15:05Z

Weaknesses