Executive brief
libheif is a decoder and encoder for HEIF and AVIF image formats used by many applications to handle modern image files. When the uncompressed codec feature is enabled, an attacker can craft a malicious image file with incorrectly sized tile data that causes a heap buffer overflow, potentially leading to data corruption, information disclosure, or remote code execution.
Technical details
The vulnerability exists in the unci encoder's tile handling path when WITH_UNCOMPRESSED_CODEC is enabled. The heif_context_add_image_tile() function accepts independently constructed tiles whose component-plane dimensions do not match the tile geometry, and passes them to unc_encoder::encode_tile() which lacks validation and sizes its output buffer based on the prototype image's configuration while copying from the tile's actual dimensions, causing a heap buffer overflow. The fix adds comprehensive validation gates to encode_tile() that verify colorspace, chroma format, component properties, and plane sizes against the prototype before encoding.
Affected products
- strukturag libheif before 1.23.2
Timeline
- 2026-09-18: disclosed
- 2026-08-24: patched