VDB

CVE-2026-84446

CVE-2026-84446 PUBLISHED CVSS 7.5 HIGH

Reported by GitHub_M · Published September 18, 2026

libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1.23.2, crafted HEIF sequence timing and edit-list data can make Track::init_sample_timing_table() compute a logical m_num_output_samples value that exceeds the uint32_t counters used by Track_Visual::decode_next_image_sample() and Track::get_next_sample_raw_data(). The resulting comparison can never reach the oversized output count, causing non-terminating decode or raw-sample loops and bypassing max_sequence_frames. The same sequence path repeatedly calls Box_stts::get_sample_duration() and allocates Chunk::m_sample_ranges and Track::m_presentation_timeline outside MemoryHandle accounting, allowing severe CPU and memory exhaustion from a small file. This issue is fixed in version 1.23.2.

EPSS 0.46% · 39.4th percentile

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
0.46%
39.4th percentile

Affected Products

VendorProductVersions
strukturaglibheif< 1.23.2
strukturaglibheif< 1.23.2

Timeline

  • Sep 8, 2026 CVE Published
  • Sep 19, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›