Executive brief
libheif is an open-source library used to encode and decode HEIF and AVIF image files, commonly used in image viewers and web browsers. A vulnerability exists where processing a specially crafted image file can cause the software to crash or potentially leak sensitive information from the computer's memory. This occurs when the library incorrectly handles images that use different levels of detail for color and transparency. Users are advised to update to version 1.22.0 to resolve this issue.
Technical details
A heap buffer over-read exists in libheif/pixelimage.cc within the HeifPixelImage::overlay() function. The vulnerability is triggered when compositing an overlay image (iovl) where the child image has a different bit depth for the alpha channel compared to the color channels. In this scenario, the function incorrectly uses the color channel stride (in_stride) to index into the alpha plane instead of the dedicated alpha_stride, leading to reads beyond the allocated alpha buffer. An attacker can exploit this via a crafted HEIF file to cause a denial of service (application crash) or potentially disclose adjacent heap memory by embedding leaked bytes into the decoded output pixels. The issue is fixed in version 1.22.0.
Affected products
- strukturag libheif <= 1.21.2
Timeline
- 2026-05-19: disclosed
- 2026-05-19: patched: Fixed in version 1.22.0
- 2026-05-19: advisory