Executive brief
libheif is a decoder and encoder for HEIF and AVIF image formats. A crafted image file with compressed metadata can cause the library to decompress data without size limits, consuming unbounded memory and crashing the application. An attacker can create a small malicious image file that triggers this denial-of-service when opened.
Technical details
The vulnerability exists in decompress_brotli() and do_inflate() functions which lack effective output-size bounds. The brotli path has no output limit, while the zlib path only checks a small temporary buffer in a code branch that valid streams do not reach. Additionally, overlapping ICEF units can decompress the same payload repeatedly, amplifying memory consumption. HeifContext::interpret_heif_file_images() processes multiple compressed metadata items during file opening, allowing an attacker-crafted file to exhaust memory during the parse phase.
Affected products
- Struktur AG libheif 1.19.0 to 1.23.1
Timeline
- 2026-09-18: disclosed: CVE-2026-84384 published
- 2026-08-24: patched: Fix committed to master branch
- 2026-08-25: patched: Version 1.23.2 released with security fix