Executive brief
libheif is a widely used software library for encoding and decoding HEIF and AVIF image files. A vulnerability in the way it parses certain image sequences allows a specially crafted, small file (as small as 800 bytes) to trap the software in an infinite loop. This causes the affected application to consume 100% of the CPU indefinitely without crashing or logging an error. In a business context, this can lead to a silent Denial of Service (DoS), where image processing servers or applications become unresponsive, potentially halting operations or exhausting cloud computing resources without triggering standard crash-monitoring alerts.
Technical details
An infinite loop vulnerability exists in libheif versions 1.21.2 and earlier within the Box_stts::get_sample_duration() and Box_ctts::get_sample_offset() functions in libheif/sequences/seq_boxes.cc. The root cause is a missing loop increment variable; when a crafted HEIF file contains a 'stts' (sample-to-time) box entry with a sample_count of zero, the loop fails to progress while the exit condition remains unfulfilled. An attacker can bypass library consistency checks by providing multiple entries that sum to a valid total. The vulnerability is triggered during the initial file parsing phase (heif_context_read_from_file) before any image decoding or user interaction occurs. This results in a permanent hang of the process with 100% CPU utilization and no error logs, effectively bypassing crash-based monitoring systems. The issue is resolved in version 1.22.0.
Affected products
- strukturag libheif <= 1.21.2
Timeline
- 2026-05-19: advisory: GHSA-j9g7-q9hv-gq8c published
- 2026-05-19: patched: Version 1.22.0 released
- 2026-05-19: disclosed: CVE-2026-32739 published to NVD