AI analysis
libheif versions 1.19.0 through before 1.23.2 fail to limit accumulated decompressed output when parsing crafted HEIF or AVIF files: the brotli path (decompress_brotli()) applies no output bound at all, the zlib path (do_inflate()) checks only a small temporary buffer in a branch that valid streams never reach, and neither path performs MemoryHandle accounting. Overlapping icef units can force the same compressed payload to be decompressed repeatedly, and HeifContext::interpret_heif_file_images() processes multiple compressed mime-metadata items while opening the file, so a very small malicious file can drive memory consumption without limit and terminate the process. An attacker who can submit a crafted HEIF or AVIF file to any application or service built on an affected libheif (image upload processors, thumbnailers, conversion pipelines, desktop viewers) gains a remote denial-of-service with no confidentiality or integrity impact (CVSS 7.5, availability only). Anyone packaging or embedding libheif 1.19.0 to before 1.23.2 and decoding untrusted files is affected; the flaw is fixed in version 1.23.2. No public proof-of-concept is known and the issue is not listed in CISA KEV, so no exploitation has been reported.
What to do: Upgrade libheif to 1.23.2 (or apply a distribution backport) anywhere the library decodes untrusted files, and check bundled consumers such as ImageMagick, libvips-based stacks and thumbnail services for the 1.19.0-1.23.1 range. Until patched, restrict or reject user-supplied HEIF/AVIF uploads and run decoding in sandboxed worker processes with hard memory limits (cgroup or rlimit caps) so an OOM kill cannot take down the host service.
Affected
| struktur AG (libheif project) libheif | >= 1.19.0, < 1.23.2 (fixed in 1.23.2) |
Estimated exposure
massmillions of deployments plausibly embed a vulnerable libheif via Linux distro packages and bundled image libraries (rough order-of-magnitude estimate) — libheif is the standard open-source HEIF/AVIF codec shipped by major Linux distributions and linked into numerous image tools and server-side image pipelines, but no public scan quantifies internet-reachable decoders, so only services that…
Description
libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.2, crafted HEIF or AVIF mime metadata and unci image data can cause decompress_brotli() and do_inflate() to grow accumulated output without an effective size limit or MemoryHandle accounting. The brotli path has no output bound, while the zlib path checks only a small temporary buffer in a branch that valid streams do not reach, and overlapping icef units can decompress the same payload repeatedly. HeifContext::interpret_heif_file_images() processes multiple compressed metadata items during file opening, allowing a small file to consume unbounded memory and terminate the process. This issue is fixed in version 1.23.2.