strukturag.libheif is vulnerable to Out-of-bounds Write
98
Critical Risk
libheif assumes a decoded image's declared width and height describe every channel plane and that each channel is backed by a single plane. Parsing a HEIC file that uses identity (iden) and auxiliary (auxl) derived-item chains violates these invariants, so plane accessors index buffers using mismatched geometry. This produces out-of-bounds reads and writes during decoding that can be leveraged for remote code execution. The fix validates plane geometry and channel-to-plane relationships before indexing.
You are affected if you decode or parse untrusted HEIF/HEIC files with a vulnerable version.
strukturag.libheif is vulnerable to Out-of-bounds Write in versions 0.0.1 - 1.23.1.
Upgrade the strukturag.libheif library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.