Junglewise Threat Intelligence

CVE-2026-84444: libheif heap buffer overflow in uncompressed encoder

CVE-2026-84444 · Severity: high · CVSS 7.4 · Published 2026-09-18

Technologies: Strukturag Libheif. Vendors: Strukturag.

Executive brief

libheif is a decoder and encoder for HEIF and AVIF image formats used by many applications to handle modern image files. When the uncompressed codec feature is enabled, an attacker can craft a malicious image file with incorrectly sized tile data that causes a heap buffer overflow, potentially leading to data corruption, information disclosure, or remote code execution.

Technical details

The vulnerability exists in the unci encoder's tile handling path when WITH_UNCOMPRESSED_CODEC is enabled. The heif_context_add_image_tile() function accepts independently constructed tiles whose component-plane dimensions do not match the tile geometry, and passes them to unc_encoder::encode_tile() which lacks validation and sizes its output buffer based on the prototype image's configuration while copying from the tile's actual dimensions, causing a heap buffer overflow. The fix adds comprehensive validation gates to encode_tile() that verify colorspace, chroma format, component properties, and plane sizes against the prototype before encoding.

Affected products

  • strukturag libheif before 1.23.2

Timeline

  • 2026-09-18: disclosed
  • 2026-08-24: patched

References

Related threats