strukturag.libheif is vulnerable to Denial of Service (DoS)
75
High Risk
libheif follows the alpha auxiliary (auxl) edge while decoding an image, but the cycle guard is recorded only on a copy of the decode state, so the parent decode frame never observes it. A crafted file whose alpha auxiliary items reference each other re-enters decode_image on an item whose non-recursive decode mutex is still held, permanently deadlocking the decode thread. This lets a single malformed file hang decoding indefinitely. The fix records the item id on the decode path so the reference cycle is detected.
You are affected if you are using a version that falls within the vulnerable range.
strukturag.libheif is vulnerable to Denial of Service (DoS) in versions 1.22.0 - 1.23.2.
Upgrade the strukturag.libheif library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.