Impact
The vulnerability arises from an integer overflow in the range check used by libheif’s uncompressed tile decoder. When a crafted HEIF or AVIF file contains a large range_start_offset and range_size, the overflow causes the bounds comparison to incorrectly succeed, allowing the decoder to call memcpy() with an invalid source pointer and a length that exceeds the source buffer. This out‑of‑bounds read can trigger a crash during tile decoding, which manifests as a denial of service. The flaw does not provide direct access to sensitive data, but it can disrupt any service that relies on libheif to process image files.
Affected Systems
Versions of strukturag libheif from 1.19.0 up through 1.23.2 are vulnerable. The problem is addressed in release 1.23.3, which removes the wrap‑around range check. To avoid the issue, systems must upgrade to libheif 1.23.3 or later or otherwise disable uncompressed tile processing.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity vulnerability. The EPSS score is below 1%, indicating low exploitation probability. The flaw is not listed in the CISA KEV catalog and no public exploit has been reported. Based on the description, the most likely attack vector is local or remote file processing where an attacker can supply a crafted HEIF/AVIF image to a system that invokes libheif for decoding; any facility that accepts such images could be impacted if the vulnerable decoder path is reachable.
OpenCVE Enrichment
Debian DSA