Executive brief
libheif is a software library used by many applications to process HEIF and AVIF image files. A security flaw in how the library handles certain image layouts allows a malicious image file to corrupt the computer's memory when the image is opened or previewed. This could allow an attacker to crash the application or potentially take control of the system, leading to data theft or unauthorized access.
Technical details
A heap-based buffer overflow exists in libheif versions 1.21.2 and prior within the HeifPixelImage::copy_image_to() function in pixelimage.cc. The vulnerability is caused by a rounding mismatch during the calculation of chroma plane offsets and copy heights when processing YCbCr 4:2:0 images with specific grid configurations (e.g., a 1x4 grid of odd-height tiles). An attacker can exploit this by providing a crafted HEIF/AVIF file that, when decoded, writes 64 bytes of attacker-controlled chroma pixel data past the end of a heap allocation. This can lead to heap corruption, denial of service, or remote code execution through heap grooming. The issue is fixed in version 1.22.0.
Affected products
- strukturag libheif <= 1.21.2
Timeline
- 2026-05-19: disclosed
- 2026-05-19: patched: Fixed in version 1.22.0
- 2026-05-19: advisory