Intel

AIKIDO-2026-370504

strukturag.libheif is vulnerable to Denial of Service (DoS)

Denial of Service (DoS)GHSA-prgh-72vc-3xmc Published 4 days ago

87

High Risk

This Affects:

C++strukturag.libheif
1.22.0 - 1.23.3
Fixed in 1.23.4
Are you affected? Scan for Free

TL;DR

libheif holds a non-recursive per item decode mutex across nested decodes and decodes grid tiles in parallel. A crafted file whose tiles reference each other through alpha auxiliary edges makes two worker threads acquire the same item mutexes in opposite order, producing a permanent deadlock that the per path cycle guard cannot detect across threads. This hangs decoding of a malformed grid image. The fix rejects cyclic decode reference graphs before any decoding begins.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

strukturag.libheif is vulnerable to Denial of Service (DoS) in versions 1.22.0 - 1.23.3.

How to fix this

Upgrade the strukturag.libheif library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform