Junglewise Threat Intelligence

CVE-2026-32739: Strukturag libheif infinite loop in Box_stts::get_sample_duration

CVE-2026-32739 · Severity: medium · CVSS 6.5 · Published 2026-05-19

Technologies: struktur AG Libheif, Strukturag Libheif. Vendors: struktur AG, Strukturag.

Executive brief

libheif is a widely used software library for encoding and decoding HEIF and AVIF image files. A vulnerability in the way it parses certain image sequences allows a specially crafted, small file (as small as 800 bytes) to trap the software in an infinite loop. This causes the affected application to consume 100% of the CPU indefinitely without crashing or logging an error. In a business context, this can lead to a silent Denial of Service (DoS), where image processing servers or applications become unresponsive, potentially halting operations or exhausting cloud computing resources without triggering standard crash-monitoring alerts.

Technical details

An infinite loop vulnerability exists in libheif versions 1.21.2 and earlier within the Box_stts::get_sample_duration() and Box_ctts::get_sample_offset() functions in libheif/sequences/seq_boxes.cc. The root cause is a missing loop increment variable; when a crafted HEIF file contains a 'stts' (sample-to-time) box entry with a sample_count of zero, the loop fails to progress while the exit condition remains unfulfilled. An attacker can bypass library consistency checks by providing multiple entries that sum to a valid total. The vulnerability is triggered during the initial file parsing phase (heif_context_read_from_file) before any image decoding or user interaction occurs. This results in a permanent hang of the process with 100% CPU utilization and no error logs, effectively bypassing crash-based monitoring systems. The issue is resolved in version 1.22.0.

Affected products

  • strukturag libheif <= 1.21.2

Timeline

  • 2026-05-19: advisory: GHSA-j9g7-q9hv-gq8c published
  • 2026-05-19: patched: Version 1.22.0 released
  • 2026-05-19: disclosed: CVE-2026-32739 published to NVD

References

Related threats