Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-84383: libheif before 1.23.2 can cause memory corruption
CVE-2026-84383 · published 21 days ago
Summary
The libheif library, which handles HEIF and AVIF image files, can be tricked by a specially crafted image into writing data outside its allocated memory. This can lead to crashes or other unexpected behavior. Upgrade libheif to version 1.23.2 or later to resolve the issue.
What to do
- Update debian libheif to version 1.23.2-1.
- Update bellsoft libheif to version 1.23.4-r0.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| Debian:14 | debian | libheif |
< 1.23.2-1 Fix: upgrade to 1.23.2-1
|
| Ubuntu:Pro:18.04:LTS | canonical | libheif | All versions |
| – | strukturag | libheif | >= 1.22.0, < 1.23.2 |
| Alpaquita:stream | bellsoft | libheif |
>= 1.20.2-r2, < 1.23.4-r0 Fix: upgrade to 1.23.4-r0
|
Original advisory text
BELL-CVE-2026-84383
libheif is a HEIF and AVIF file format decoder and encoder. From 1.22.0 until 1.23.2, a crafted HEIF, HEIC, or AVIF item graph using nested iden and auxl references can make HeifPixelImage::transfer_channel_from_image_as() append duplicate Alpha planes with different bit depths to m_storage. HeifPixelImage::scale_nearest_neighbor() in libheif/image/pixelimage.cc allocates the destination Alpha plane using the first plane's 8-bit depth, then iterates a later 10-bit or 12-bit Alpha component and writes uint16_t samples into the same 8-bit allocation. The output geometry controls the overflow extent and the encoded sample values control the data written, allowing a remote file processed by heif_decode_image() to cause a heap out-of-bounds write. This issue is fixed in version 1.23.2.
References
- https://ubuntu.com/security/CVE-2026-84383 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-84383 Third Party Advisory
- https://github.com/strukturag/libheif/security/advisories/GHSA-g89c-p67h-r497
- https://github.com/strukturag/libheif/commit/f4fb8bde4704ebb46e46ff9fb94407c9774...
- https://github.com/strukturag/libheif/releases/tag/v1.23.2
- https://security-tracker.debian.org/tracker/CVE-2026-84383 Vendor Advisory
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/84xxx/CVE-2026-84383... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-84383 Vendor Advisory
- https://docs.bell-sw.com/security/cves/CVE-2026-84383 Vendor Advisory
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Severity
9.8
Critical
Type
CWE-787Out-of-bounds Write
Timeline
Published18 Sep 2026
Updated9 Oct 2026
First seen4 Sep 2026
Sources
DEBIAN-CVE-2026-84383 · OSV
UBUNTU-CVE-2026-84383 · OSV
CVE-2026-84383 · NVD
CVE-2026-84383 · MITRE
CVE-2026-84383 · OSV
GHSA-g89c-p67h-r497 · GHSA
BELL-CVE-2026-84383 · OSV
Track software like this
Free during beta