CVE-2026-50142: CWE-190: Integer Overflow or Wraparound in strukturag libheif
A high-severity integer overflow vulnerability exists in libheif versions 1.19.0 through 1.22.999, affecting the parsing of HEIF sequences with the msf1 brand. The flaw allows crafted input to cause unbounded heap allocation due to improper bounds checking and 32-bit arithmetic wraparound, potentially leading to memory exhaustion and process crashes. This issue is fixed in version 1.23.0.
AI Analysis
Technical Summary
libheif, a HEIF and AVIF file format decoder and encoder, contains an integer overflow or wraparound vulnerability (CWE-190) in versions 1.19.0 up to but not including 1.23.0. Specifically, when processing a crafted HEIF sequence with the msf1 brand via heif_context_read_from_memory(), the Box_stsz::parse() function applies max_sequence_frames only to variable-size samples, allowing an attacker-controlled sample_count in fixed-size mode without bounds. Additionally, Track::load() uses 32-bit arithmetic to add current_sample_idx and samples_per_chunk, enabling bypass of consistency checks through wraparound. These incorrect calculations lead to excessive memory allocation in Chunk::Chunk(), causing potential gigabyte-scale heap allocations that can crash or stall the process due to memory exhaustion. The vulnerability is addressed in libheif version 1.23.0.
Potential Impact
Exploitation of this vulnerability can cause a denial of service by exhausting system memory, crashing, or stalling the affected process. There is no indication of confidentiality or integrity impact. The CVSS score of 7.5 reflects a high severity denial-of-service impact with no privileges or user interaction required.
Mitigation Recommendations
Upgrade libheif to version 1.23.0 or later, where this vulnerability is fixed. No other mitigation or workaround is indicated by the vendor advisory.
CVE-2026-50142: CWE-190: Integer Overflow or Wraparound in strukturag libheif
Description
A high-severity integer overflow vulnerability exists in libheif versions 1.19.0 through 1.22.999, affecting the parsing of HEIF sequences with the msf1 brand. The flaw allows crafted input to cause unbounded heap allocation due to improper bounds checking and 32-bit arithmetic wraparound, potentially leading to memory exhaustion and process crashes. This issue is fixed in version 1.23.0.
CVSS v3.1
Score 7.5high
Affected software
strukturag
libheif
pkg:github/strukturag/libheifRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
libheif, a HEIF and AVIF file format decoder and encoder, contains an integer overflow or wraparound vulnerability (CWE-190) in versions 1.19.0 up to but not including 1.23.0. Specifically, when processing a crafted HEIF sequence with the msf1 brand via heif_context_read_from_memory(), the Box_stsz::parse() function applies max_sequence_frames only to variable-size samples, allowing an attacker-controlled sample_count in fixed-size mode without bounds. Additionally, Track::load() uses 32-bit arithmetic to add current_sample_idx and samples_per_chunk, enabling bypass of consistency checks through wraparound. These incorrect calculations lead to excessive memory allocation in Chunk::Chunk(), causing potential gigabyte-scale heap allocations that can crash or stall the process due to memory exhaustion. The vulnerability is addressed in libheif version 1.23.0.
Potential Impact
Exploitation of this vulnerability can cause a denial of service by exhausting system memory, crashing, or stalling the affected process. There is no indication of confidentiality or integrity impact. The CVSS score of 7.5 reflects a high severity denial-of-service impact with no privileges or user interaction required.
Mitigation Recommendations
Upgrade libheif to version 1.23.0 or later, where this vulnerability is fixed. No other mitigation or workaround is indicated by the vendor advisory.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-06-03T18:49:32.275Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a84d00bc6e8be0332c73aff
Added to database: 08/18/2026, 21:35:07 UTC
Last enriched: 09/11/2026, 10:32:33 UTC
Last updated: 10/02/2026, 06:08:14 UTC
Views: 67
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.