Intel

AIKIDO-2026-179573

strukturag.libheif is vulnerable to Uncontrolled Resource Consumption

Uncontrolled Resource ConsumptionGHSA-x8xm-cm2c-cfc8 Published 6 days ago

75

High Risk

This Affects:

C++strukturag.libheif
0.0.1 - 1.23.1
Fixed in 1.23.2
Are you affected? Scan for Free

TL;DR

libheif follows chains of derived-image references such as grid, overlay, and identity items without caching decode results or accounting for the allocations. A file with indirect reference chains forces a base image to be decoded hundreds of times and pre-allocates large tile-offset vectors outside the memory budget. Opening or decoding such a file leads to denial of service. The fix adds decode-result caching and enforces memory limits on the affected allocations.

Who does this affect?

You are affected if you decode untrusted HEIF files with a vulnerable version.

Background info

strukturag.libheif is vulnerable to Uncontrolled Resource Consumption in versions 0.0.1 - 1.23.1.

How to fix this

Upgrade the strukturag.libheif library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform