Heap buffer overflow in scale_nearest_neighbor() via duplicate Alpha planes from nested iden/auxl items
github.com | vulnerability | Critical | #rce | #memory-corruption | #vulnerability | #heap-buffer-overflow | #image-parsing | #heic | #libheif | #heap-overflow | #ghsa-g89c-p67h-r497 | #isobmff
Summary
Critical libheif heap overflow (GHSA-g89c-p67h-r497): nested iden/auxl items duplicate Alpha planes so scaling writes 16-bit samples into a 1-byte buffer; a crafted five-item ISOBMFF file triggers it.
Why it matters
A critical, network-reachable image-decoding flaw can turn an attacker-supplied HEIC/HEIF/AVIF file into code execution; upgrade libheif to v1.23.2.
- Vendor
- strukturag
- Product
- libheif
- Affected versions
- <= v1.23.1; fixed in v1.23.2
- CVSS
- 9.8
- Published
- Collected
Skip to content