Junglewise Threat Intelligence

CVE-2026-84450: libheif assertion failure in clap property crop calculation

CVE-2026-84450 · Severity: medium · CVSS 4.3 · Published 2026-09-18

Technologies: Strukturag Libheif. Vendors: Strukturag.

Executive brief

libheif is a decoder and encoder for HEIF and AVIF image formats. A crafted image file with an oversized width or height property combined with a crop region property can trigger an assertion failure in builds compiled with debugging enabled, causing the application to abort. Release builds compute invalid crop geometry instead, which the tiling API may then reject as exceeding security limits.

Technical details

A clap (crop/aperture) property combined with an ispe (image spatial extents) dimension exceeding INT32_MAX+1 reaches the Fraction constructor through Box_clap::left_rounded() or Box_clap::top_rounded(), which only asserts its input range. This causes abort in assert-enabled builds, or computes incorrect crop geometry in release builds. The fix replaces the asserting constructor with error-returning factories and validates image size at the Box_clap::get_crop() entry point.

Affected products

  • strukturag libheif 1.19.0 to 1.23.2

Timeline

  • 2026-09-18: disclosed
  • 2026-09-01: patched

References

Related threats