AI analysis
libheif, a widely used open-source HEIF and AVIF decoder/encoder library, contains a logic flaw (CWE-835) in which crafted HEIF sequence timing and edit-list data cause Track::init_sample_timing_table() to compute an m_num_output_samples value that exceeds the uint32_t counters used in Track_Visual::decode_next_image_sample() and Track::get_next_sample_raw_data(). Because the loop condition can never reach the oversized output count, decoding or raw-sample extraction enters a non-terminating loop, bypasses the max_sequence_frames safeguard, and repeatedly calls Box_stts::get_sample_duration() while allocating Chunk::m_sample_ranges and Track::m_presentation_timeline outside MemoryHandle accounting. An attacker who can supply a small malicious HEIF file to a system using a vulnerable libheif can therefore inflict severe CPU and memory exhaustion, i.e., a denial of service, with no confidentiality or integrity impact. Any deployment that decodes untrusted HEIF/AVIF files with libheif prior to 1.23.2 is affected, including image-upload and thumbnailing services, desktop and mobile applications, and anything embedding the library via distributions or image-processing stacks. No public proof-of-concept is known, the issue is not in CISA's KEV, and no in-the-wild exploitation has been reported.
What to do: Upgrade libheif to version 1.23.2 or later, including rebuilds shipped by your Linux distribution or application vendor. Until patched, restrict or validate untrusted HEIF/AVIF uploads, and apply decode timeouts and CPU/memory limits to image-processing workers. Check installed library versions and dependencies (e.g., via your package manager or SBOM) to confirm whether libheif is present and from which application it is reachable.
Affected
| strukturag libheif | all versions prior to 1.23.2 (fixed in 1.23.2) |
Estimated exposure
masslikely millions of installations ship a vulnerable libheif (packaged in mainstream Linux distributions and embedded in image-processing software), though the… — libheif is the standard HEIF/AVIF decoding library distributed by major Linux distributions and bundled into numerous image tools and application stacks, so the deployed base is very large, but exploitability depends on each deployment…
Description
libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1.23.2, crafted HEIF sequence timing and edit-list data can make Track::init_sample_timing_table() compute a logical m_num_output_samples value that exceeds the uint32_t counters used by Track_Visual::decode_next_image_sample() and Track::get_next_sample_raw_data(). The resulting comparison can never reach the oversized output count, causing non-terminating decode or raw-sample loops and bypassing max_sequence_frames. The same sequence path repeatedly calls Box_stts::get_sample_duration() and allocates Chunk::m_sample_ranges and Track::m_presentation_timeline outside MemoryHandle accounting, allowing severe CPU and memory exhaustion from a small file. This issue is fixed in version 1.23.2.