Heap Corruption in libheif's Image Decoding and Encoding
CVE-2026-62291
5.3MEDIUM
What is CVE-2026-62291?
A vulnerability in libheif prior to version 1.23.1 allows for heap corruption when decoding crafted image sequences. This occurs due to a failure in dimension validation between the primary and auxiliary planes during the decode and re-encode process. The improper handling of alpha plane dimensions can lead to out-of-bounds writes and reads, which may allow attackers to manipulate memory, potentially compromising the application's stability and security. Updating to version 1.23.1 resolves this critical issue, ensuring proper dimension checks are enforced.
Affected Version(s)
libheif < 1.23.1
