CVE-2026-84448 Overview
CVE-2026-84448 is an out-of-bounds read vulnerability [CWE-125] in libheif, an open-source HEIF and AVIF file format decoder and encoder maintained by Struktur AG. The flaw affects versions prior to 1.23.2. The public heif_region_item_add_region_inline_mask_data() function accepts a mask_data_len argument without verifying that it matches the byte count required by the supplied width and height. A later call to heif_region_get_mask_image() derives the read length from the region geometry, causing heif_region_get_inline_mask_image() to read past the heap allocation. The file-parsing path is not affected because it validates the canonical mask size.
Critical Impact
Applications that construct region metadata through the libheif writer API can leak adjacent heap memory into a returned monochrome mask image or crash when accessing unmapped pages.
Affected Products
- libheif versions prior to 1.23.2
- Applications embedding libheif that call heif_region_item_add_region_inline_mask_data() through the writer API
- Downstream image processing pipelines and encoders using the libheif region metadata interface
Discovery Timeline
- 2026-09-18 - CVE-2026-84448 published to NVD
- 2026-09-24 - Last updated in NVD database
Technical Details for CVE-2026-84448
Vulnerability Analysis
The vulnerability resides in libheif/api/libheif/heif_regions.cc. The writer API function heif_region_item_add_region_inline_mask_data() stores a caller-supplied buffer along with width, height, and mask_data_len values without cross-validating them. Inline masks are packed at one bit per pixel with no row padding, so the canonical size is (width * height + 7) / 8 bytes.
When a subsequent reader call invokes heif_region_get_inline_mask_image(), the read length is recomputed from the geometry rather than the stored buffer length. If the caller stored a smaller buffer than the geometry requires, the copy routine reads beyond the heap allocation. Adjacent heap bytes are then copied into the returned monochrome mask image, exposing potentially sensitive data or triggering a crash on invalid memory access.
Root Cause
The root cause is missing input validation in the writer API. The function trusts the caller to provide consistent geometry and buffer length, while the reader path assumes the stored buffer already satisfies the canonical size. This asymmetry between the writer and reader creates a boundary condition error where the reader over-reads the under-sized allocation.
Attack Vector
Exploitation requires local access and the ability to influence parameters passed to the libheif writer API. An attacker who controls region metadata construction can supply mismatched width, height, and mask_data_len values, then trigger the mask reader to leak adjacent heap contents. The file-parsing path validates the canonical mask size and is not exploitable through crafted HEIF or AVIF files.
size_t mask_data_len,
heif_region** out_region)
{
+ if (out_region) {
+ *out_region = nullptr;
+ }
+
+ if (mask_data == nullptr) {
+ return heif_error_null_pointer_argument;
+ }
+
+ if (width == 0 || height == 0) {
+ return {heif_error_Invalid_input, heif_suberror_Invalid_region_data,
+ "Inline mask region has zero width or height"};
+ }
+
+ // The mask is stored with one bit per pixel, no padding between rows. Only the
+ // very last byte is padded. This is the same canonical size that the file parser
+ // (RegionGeometry_InlineMask::parse) and the reader (heif_region_get_mask_image)
+ // compute from the geometry. The caller-supplied buffer must hold exactly that
+ // many bytes: a shorter buffer would make the reader run off the end of the
+ // allocation, and a longer buffer indicates that the caller's geometry and mask
+ // data disagree, which we reject rather than silently discard.
+ uint64_t mask_size = (static_cast<uint64_t>(width) * height + 7) / 8;
+ if (mask_size > std::numeric_limits<size_t>::max()) {
+ return {heif_error_Memory_allocation_error, heif_suberror_Security_limit_exceeded,
+ "Inline mask size overflow"};
+ }
+
+ if (mask_data_len != static_cast<size_t>(mask_size)) {
Source: GitHub Commit 646d85f
Detection Methods for CVE-2026-84448
Indicators of Compromise
- Unexpected process crashes or SIGSEGV signals originating in libheif region handling functions
- Anomalous monochrome mask image output containing patterns inconsistent with source geometry
- Application logs referencing heif_region_get_inline_mask_image() faults or heap corruption reports from allocator instrumentation
Detection Strategies
- Inventory installed libheif versions across build systems, containers, and endpoints; flag any version below 1.23.2
- Use software composition analysis (SCA) tools to identify applications statically or dynamically linked against vulnerable libheif builds
- Run AddressSanitizer or Valgrind on applications that exercise the writer API to surface out-of-bounds reads at runtime
Monitoring Recommendations
- Monitor endpoint telemetry for crash signatures involving image processing binaries that depend on libheif
- Track package updates and CI/CD pipeline events to confirm patched libheif builds propagate through production
- Alert on unexpected memory access violations in services that ingest or generate HEIF and AVIF region metadata
How to Mitigate CVE-2026-84448
Immediate Actions Required
- Upgrade libheif to version 1.23.2 or later across all environments that link the library
- Rebuild and redeploy downstream applications, container images, and packages that statically bundle libheif
- Audit application code that calls heif_region_item_add_region_inline_mask_data() to ensure mask_data_len equals (width * height + 7) / 8
Patch Information
The issue is fixed in libheif version 1.23.2. The patch in commit 646d85f adds explicit validation in the writer API: it rejects null buffers, zero dimensions, size overflow, and any mask_data_len value that does not equal the canonical (width * height + 7) / 8 byte count. Refer to the GitHub Security Advisory GHSA-p58j-h3vm-3fp5 and the libheif v1.23.2 release notes for full details.
Workarounds
- Validate mask_data_len in application code before invoking the writer API, ensuring it equals (width * height + 7) / 8
- Restrict use of the writer API to trusted local processes until patched builds are deployed
- Avoid returning inline mask image data across trust boundaries in unpatched deployments to limit information disclosure
# Verify installed libheif version and upgrade
heif-info --version
# Debian/Ubuntu
sudo apt update && sudo apt install --only-upgrade libheif1
# Fedora/RHEL
sudo dnf upgrade libheif
# Build from source
git clone --branch v1.23.2 https://github.com/strukturag/libheif.git
cd libheif && mkdir build && cd build
cmake --preset=release .. && cmake --build .
sudo cmake --install .
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
