Description
libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.3, the no-icef full-item branch of unc_decoder::get_compressed_image_data_uncompressed() in libheif/codecs/uncompressed/unc_decoder.cc retains an addition-based range check that can wrap when a crafted uncompressed tile grid produces a large range_start_offset and range_size. The overflow makes the bounds comparison pass and allows heif_image_handle_decode_image_tile() to call memcpy() with an invalid source pointer and a very large length when decoding a valid high-index advertised tile. This incomplete remediation of CVE-2026-62292 can reliably crash tile-processing applications, while whole-image decoding is not claimed to reach the demonstrated path. This issue is fixed in version 1.23.3.
Published: 2026-09-18
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via out-of-bounds read
Action: Immediate Patch
AI Analysis

Impact

The vulnerability arises from an integer overflow in the range check used by libheif’s uncompressed tile decoder. When a crafted HEIF or AVIF file contains a large range_start_offset and range_size, the overflow causes the bounds comparison to incorrectly succeed, allowing the decoder to call memcpy() with an invalid source pointer and a length that exceeds the source buffer. This out‑of‑bounds read can trigger a crash during tile decoding, which manifests as a denial of service. The flaw does not provide direct access to sensitive data, but it can disrupt any service that relies on libheif to process image files.

Affected Systems

Versions of strukturag libheif from 1.19.0 up through 1.23.2 are vulnerable. The problem is addressed in release 1.23.3, which removes the wrap‑around range check. To avoid the issue, systems must upgrade to libheif 1.23.3 or later or otherwise disable uncompressed tile processing.

Risk and Exploitability

The CVSS score of 6.5 indicates a medium severity vulnerability. The EPSS score is below 1%, indicating low exploitation probability. The flaw is not listed in the CISA KEV catalog and no public exploit has been reported. Based on the description, the most likely attack vector is local or remote file processing where an attacker can supply a crafted HEIF/AVIF image to a system that invokes libheif for decoding; any facility that accepts such images could be impacted if the vulnerable decoder path is reachable.

Generated by OpenCVE AI on September 19, 2026 at 17:16 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade libheif to version 1.23.3 or later, which removes the unsafe range check.
  • If an immediate upgrade is not possible, configure the consuming application to skip decoding of uncompressed tiles or to reject HEIF/AVIF files that declare large tile indices, thereby preventing the out‑of‑bounds read path.
  • Implement runtime monitoring for segmentation faults or abnormal memory access errors produced by libheif, and alert on such events so that issues can be investigated and mitigated promptly.

Generated by OpenCVE AI on September 19, 2026 at 17:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6523-1 libheif security update
History

Fri, 25 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Struktur
Struktur libheif
Vendors & Products Struktur
Struktur libheif

Fri, 18 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
Description libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.3, the no-icef full-item branch of unc_decoder::get_compressed_image_data_uncompressed() in libheif/codecs/uncompressed/unc_decoder.cc retains an addition-based range check that can wrap when a crafted uncompressed tile grid produces a large range_start_offset and range_size. The overflow makes the bounds comparison pass and allows heif_image_handle_decode_image_tile() to call memcpy() with an invalid source pointer and a very large length when decoding a valid high-index advertised tile. This incomplete remediation of CVE-2026-62292 can reliably crash tile-processing applications, while whole-image decoding is not claimed to reach the demonstrated path. This issue is fixed in version 1.23.3.
Title libheif: Incomplete fix for CVE-2026-62292 leaves libheif vulnerable to an out-of-bounds read
Weaknesses CWE-125
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}


Subscriptions

Struktur Libheif
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-24T21:05:25.846Z

Reserved: 2026-09-01T20:05:09.423Z

Link: CVE-2026-84451

cve-icon Vulnrichment

Updated: 2026-09-24T21:03:47.649Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T16:17:13.320

Modified: 2026-09-24T21:18:55.527

Link: CVE-2026-84451

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:15:05Z

Weaknesses