strukturag.libheif is vulnerable to Heap-based Buffer Overflow
93
Critical Risk
HeifPixelImage::scale_nearest_neighbor can allocate an 8-bit Alpha plane from the first matching channel while later writing 16-bit samples from a duplicate Alpha created by nested iden/auxl item graphs. A crafted HEIC/HEIF/AVIF decoded through heif_decode_image therefore overflows the heap with attacker-controlled size and contents, enabling remote code execution. The fix rejects duplicate destination channels and hardens Alpha handling so nested derivation cannot underallocate then overwrite the plane.
You are affected if you are using a version that falls within the vulnerable range and your application decodes untrusted HEIC, HEIF, or AVIF images with heif_decode_image.
strukturag.libheif is vulnerable to Heap-based Buffer Overflow in versions 0.0.1 - 1.23.1.
Upgrade the strukturag.libheif library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant