Skip to main content
Vulnerability Database/CVE-2026-84451

CVE-2026-84451: libheif Buffer Overflow Vulnerability

CVE-2026-84451 is a buffer overflow in libheif HEIF and AVIF decoder affecting versions 1.19.0 to 1.23.3. The flaw allows crafted tile grids to trigger integer overflow leading to crashes. This article covers technical details, impact, and fixes.

Published:

CVE-2026-84451 Overview

CVE-2026-84451 is an integer overflow vulnerability in libheif, a widely used HEIF and AVIF file format decoder and encoder. The flaw resides in the no-icef full-item branch of unc_decoder::get_compressed_image_data_uncompressed() inside libheif/codecs/uncompressed/unc_decoder.cc. A crafted uncompressed tile grid can supply large range_start_offset and range_size values that wrap during an addition-based bounds check, allowing heif_image_handle_decode_image_tile() to invoke memcpy() with an invalid source pointer and an oversized length. The issue affects versions 1.19.0 through 1.23.2 and is an incomplete remediation of CVE-2026-62292.

Critical Impact

A crafted HEIF file can reliably crash any tile-processing application that links against vulnerable libheif releases.

Affected Products

  • libheif versions 1.19.0 through 1.23.2
  • Applications embedding libheif for HEIF or AVIF tile decoding
  • Downstream image viewers, thumbnailers, and browsers using vulnerable libheif builds

Discovery Timeline

  • 2026-09-18 - CVE-2026-84451 published to NVD
  • 2026-09-24 - Last updated in NVD database

Technical Details for CVE-2026-84451

Vulnerability Analysis

The defect is an integer overflow leading to an out-of-bounds read [CWE-125]. The vulnerable code path validates whether a requested tile range fits within a data buffer using the expression range_start_offset + range_size > data->size(). Both operands are uint64_t values derived from attacker-controlled tile grid metadata. When the sum wraps past UINT64_MAX, the comparison evaluates to false, and the check passes despite pointing outside the buffer.

The decoder then calls memcpy() with a source pointer offset beyond the buffer and a very large length. Tile-processing applications terminate on the resulting invalid read. The fix in version 1.23.3 rewrites the check in subtraction form to prevent wrap-around.

Root Cause

The root cause is unchecked arithmetic on untrusted 64-bit inputs before a size comparison. This is the same class of defect that produced CVE-2026-62292 in the sibling icef branch. The initial patch did not extend the safer comparison form to the no-icef full-item path.

Attack Vector

An attacker delivers a malformed HEIF file that advertises a high-index tile with crafted range_start_offset and range_size fields. The victim opens the file in an application that invokes heif_image_handle_decode_image_tile(). No authentication is required, and exploitation is remote when the file is delivered over the network. The advisory notes the demonstrated path is reached during tile decoding rather than whole-image decoding.

text
     *data = std::move(*dataResult);
 
-    if (range_start_offset + range_size > data->size()) {
+    // Use subtraction form to avoid a uint64_t wrap in 'range_start_offset + range_size'.
+    // A crafted tiling can make the requested tile range wrap to zero, passing the
+    // addition-form check and leading to an out-of-bounds read in the memcpy() below
+    // (GHSA-hh47-fhqr-cj2r; same root cause as the icef sibling branch above, GHSA-73p7-m7gg-w2jv).
+    if (range_start_offset > data->size() ||
+        range_size > data->size() - range_start_offset) {
       return {
         heif_error_Invalid_input,
         heif_suberror_Unspecified,

Source: GitHub commit 8bfed9a

Detection Methods for CVE-2026-84451

Indicators of Compromise

  • Unexpected crashes in processes that call libheif tile decoding APIs when opening HEIF or AVIF content
  • Segmentation faults originating in unc_decoder.cc or during heif_image_handle_decode_image_tile() execution
  • HEIF files containing unci tile grids with abnormally large range_start_offset or range_size values

Detection Strategies

  • Inventory installed packages and applications that ship libheif and flag versions between 1.19.0 and 1.23.2
  • Inspect HEIF samples with a parser that enumerates tile ranges and alert on values approaching UINT64_MAX
  • Correlate application crash telemetry with recent HEIF or AVIF file access events

Monitoring Recommendations

  • Monitor endpoint crash dumps for stack frames referencing libheif tile decoding functions
  • Track software bill of materials (SBOM) entries to identify products bundling vulnerable libheif builds
  • Log HEIF and AVIF file processing at gateways, mail scanners, and image conversion services

How to Mitigate CVE-2026-84451

Immediate Actions Required

  • Upgrade libheif to version 1.23.3 or later across all systems and dependent applications
  • Rebuild and redistribute downstream software that statically links libheif
  • Restrict processing of HEIF and AVIF files from untrusted sources until patched builds are deployed

Patch Information

The fix is included in libheif 1.23.3, published in the GitHub Release v1.23.3. The technical remediation is documented in GHSA-hh47-fhqr-cj2r and the corresponding upstream commit, which replaces the addition-form bounds check with a subtraction-based comparison.

Workarounds

  • Disable HEIF and AVIF tile decoding in applications that expose the feature as optional
  • Sandbox image decoding processes so a crash cannot affect the parent application or user session
  • Pre-filter incoming HEIF files at content gateways and reject files with malformed tile grids
bash
# Verify the installed libheif version on Linux systems
ldconfig -p | grep libheif
dpkg -l | grep libheif   # Debian/Ubuntu
rpm -qa | grep libheif   # RHEL/Fedora

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.