strukturag.libheif is vulnerable to Out-of-bounds Read
63
Medium Risk
The per channel bit-depth equality check added for the YCbCr-to-RGB conversion runs inside convert_colorspace, but Encoder::convert_colorspace_for_encoding returns early when the colorspace already matches the encoder, so an image with 10- or 12-bit luma but 8-bit chroma reaches the AOM and x265 encoder plugins unconverted. Those plugins read one-byte chroma planes at two bytes per sample, leaking heap bytes into the lossless output or aborting under encoder assertions. This is an incomplete fix of GHSA-w7mc-p8jc-p853 on the encoding path. The fix validates the input image inside each encoder plugin.
You are affected if you are using a version that falls within the vulnerable range and you encode images through the AOM or x265 encoder plugins with mismatched luma and chroma bit depths.
strukturag.libheif is vulnerable to Out-of-bounds Read in versions 1.20.0 - 1.23.3.
Upgrade the strukturag.libheif library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.