Intel

AIKIDO-2026-557846

strukturag.libheif is vulnerable to Heap-based Buffer Overflow

Heap-based Buffer OverflowGHSA-4jqm-2x34-6f6r Published 4 days ago

75

High Risk

This Affects:

C++strukturag.libheif
1.19.6 - 1.23.2
Fixed in 1.23.3
Are you affected? Scan for Free

TL;DR

The SVT-AV1 encoder plugin in libheif allocates a dummy chroma plane sized for one byte per sample but writes it through the 16-bit path when encoding high-bit-depth images that carry an alpha channel. Encoding such an image writes twice the allocated size, overflowing the heap buffer with a fixed byte pattern. This produces file-influenced heap corruption in builds that use the SVT-AV1 encoder. The fix multiplies the allocation by the per sample byte count.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and your build uses the SVT-AV1 encoder plugin to encode high-bit-depth images that include an alpha channel.

Background info

strukturag.libheif is vulnerable to Heap-based Buffer Overflow in versions 1.19.6 - 1.23.2.

How to fix this

Upgrade the strukturag.libheif library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform