CyberRota Analysis
AI-GeneratedThe vulnerability in libheif affects versions 1.22.0 to 1.23.2, allowing crafted HEIF, HEIC, or AVIF files to exploit improper handling of Alpha planes, leading to a heap out-of-bounds write. This can result in potential remote code execution or application crashes, making it critical for users of libheif to upgrade to version 1.23.2 immediately to mitigate the risk. Organizations utilizing this library for image processing should prioritize patching to protect against potential exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
libheif is a HEIF and AVIF file format decoder and encoder. From 1.22.0 until 1.23.2, a crafted HEIF, HEIC, or AVIF item graph using nested iden and auxl references can make HeifPixelImage::transfer_channel_from_image_as() append duplicate Alpha planes with different bit depths to m_storage. HeifPixelImage::scale_nearest_neighbor() in libheif/image/pixelimage.cc allocates the destination Alpha plane using the first plane's 8-bit depth, then iterates a later 10-bit or 12-bit Alpha component and writes uint16_t samples into the same 8-bit allocation. The output geometry controls the overflow extent and the encoded sample values control the data written, allowing a remote file processed by heif_decode_image() to cause a heap out-of-bounds write. This issue is fixed in version 1.23.2.