strukturag.libheif is vulnerable to Heap-based Buffer Overflow
75
High Risk
The SVT-AV1 encoder plugin in libheif allocates a dummy chroma plane sized for one byte per sample but writes it through the 16-bit path when encoding high-bit-depth images that carry an alpha channel. Encoding such an image writes twice the allocated size, overflowing the heap buffer with a fixed byte pattern. This produces file-influenced heap corruption in builds that use the SVT-AV1 encoder. The fix multiplies the allocation by the per sample byte count.
You are affected if you are using a version that falls within the vulnerable range and your build uses the SVT-AV1 encoder plugin to encode high-bit-depth images that include an alpha channel.
strukturag.libheif is vulnerable to Heap-based Buffer Overflow in versions 1.19.6 - 1.23.2.
Upgrade the strukturag.libheif library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.