Skip to main content
Vulnerability Database/CVE-2026-84383

CVE-2026-84383: libheif Buffer Overflow Vulnerability

CVE-2026-84383 is a heap buffer overflow in libheif affecting HEIF and AVIF file processing that allows remote attackers to write beyond allocated memory. This article covers technical details, affected versions, and mitigation.

Published:

CVE-2026-84383 Overview

CVE-2026-84383 is a heap out-of-bounds write vulnerability in libheif, a widely deployed HEIF and AVIF file format decoder and encoder. The flaw affects versions from 1.22.0 up to but not including 1.23.2. A crafted HEIF, HEIC, or AVIF file with nested iden and auxl item references triggers duplicate Alpha planes with mismatched bit depths, resulting in memory corruption during decode. Any application that calls heif_decode_image() on untrusted input is exposed. This includes image viewers, thumbnailers, browsers, and server-side media pipelines.

Critical Impact

Remote attackers can trigger a heap out-of-bounds write by supplying a crafted image, enabling potential arbitrary code execution with no user authentication required.

Affected Products

  • libheif versions 1.22.0 through 1.23.1
  • Applications and services embedding vulnerable libheif builds for HEIF, HEIC, or AVIF decoding
  • Linux distributions and container images shipping the affected libheif package

Discovery Timeline

  • 2026-09-18 - CVE-2026-84383 published to NVD
  • 2026-09-18 - Last updated in NVD database

Technical Details for CVE-2026-84383

Vulnerability Analysis

The vulnerability lives in libheif's pixel image handling logic. When libheif parses a HEIF item graph that nests iden (identity) and auxl (auxiliary) references, HeifPixelImage::transfer_channel_from_image_as() appends duplicate Alpha planes with differing bit depths into the internal m_storage container. This violates the implicit invariant that each channel has a single, consistent bit depth.

Downstream, HeifPixelImage::scale_nearest_neighbor() in libheif/image/pixelimage.cc allocates the destination Alpha plane sized against the first plane's 8-bit depth. The scaler then iterates a later 10-bit or 12-bit Alpha plane and writes uint16_t samples into the 8-bit allocation. The result is a heap out-of-bounds write [CWE-787].

Attackers control both the output geometry, which dictates how far the write ranges past the allocation, and the encoded sample values, which dictate the bytes written. This combination provides sufficient primitive strength to corrupt adjacent heap metadata or object pointers.

Root Cause

The root cause is missing validation of channel bit-depth consistency when merging planes derived from nested item references. The allocator and the writer disagree on element size because they consult different plane entries in m_storage.

Attack Vector

Exploitation requires only that a target application decode an attacker-supplied HEIF, HEIC, or AVIF file. No privileges or user interaction beyond opening or previewing the file are needed. Delivery paths include email attachments, web downloads, messaging apps, and server-side image processing endpoints that ingest user uploads.

No public proof-of-concept has been released. See the GitHub Security Advisory GHSA-g89c-p67h-r497 and the fix commit for technical details.

Detection Methods for CVE-2026-84383

Indicators of Compromise

  • HEIF, HEIC, or AVIF files containing nested iden and auxl item references with Alpha channels declared at differing bit depths (8-bit alongside 10-bit or 12-bit)
  • Crashes or heap corruption reports originating from processes linking libheif when decoding image files
  • ASan or glibc malloc abort messages referencing HeifPixelImage::scale_nearest_neighbor or transfer_channel_from_image_as

Detection Strategies

  • Inventory installed libheif versions across endpoints, servers, and container images, and flag any build between 1.22.0 and 1.23.1
  • Enable AddressSanitizer or hardened malloc in test environments to surface out-of-bounds writes during image processing regression tests
  • Inspect image-processing service logs for unexpected worker crashes correlated with HEIF, HEIC, or AVIF uploads

Monitoring Recommendations

  • Alert on crash-loop patterns in thumbnailer, preview, and media conversion services
  • Monitor egress from image processing hosts for anomalous outbound connections that could indicate post-exploitation activity
  • Track file uploads by MIME type and extension to identify surges in HEIF, HEIC, or AVIF traffic against ingestion pipelines

How to Mitigate CVE-2026-84383

Immediate Actions Required

  • Upgrade libheif to version 1.23.2 or later on every host, container image, and build pipeline
  • Rebuild and redeploy applications that statically link libheif against the patched release
  • Temporarily disable server-side HEIF, HEIC, and AVIF decoding on internet-facing services until patching completes

Patch Information

The issue is fixed in libheif 1.23.2. See the libheif v1.23.2 release notes and the corresponding source commit for details on the patched channel validation logic.

Workarounds

  • Block or strip HEIF, HEIC, and AVIF attachments at email and web gateways where feasible
  • Restrict uploaded image formats at application ingress to those that do not route through libheif
  • Run decoders inside sandboxed processes with seccomp filters, restricted file system access, and process isolation to contain memory corruption
bash
# Verify installed libheif version and upgrade
dpkg -l | grep libheif        # Debian/Ubuntu
rpm -qa | grep libheif        # RHEL/Fedora

# Upgrade after distribution package refresh
sudo apt update && sudo apt install --only-upgrade libheif1
sudo dnf upgrade libheif

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.