{"id":"CVE-2026-84383","summary":"libheif: Heap buffer overflow in `scale_nearest_neighbor()` via duplicate Alpha planes from nested `iden`/`auxl` items","details":"libheif is a HEIF and AVIF file format decoder and encoder. From 1.22.0 until 1.23.2, a crafted HEIF, HEIC, or AVIF item graph using nested iden and auxl references can make HeifPixelImage::transfer_channel_from_image_as() append duplicate Alpha planes with different bit depths to m_storage. HeifPixelImage::scale_nearest_neighbor() in libheif/image/pixelimage.cc allocates the destination Alpha plane using the first plane's 8-bit depth, then iterates a later 10-bit or 12-bit Alpha component and writes uint16_t samples into the same 8-bit allocation. The output geometry controls the overflow extent and the encoded sample values control the data written, allowing a remote file processed by heif_decode_image() to cause a heap out-of-bounds write. This issue is fixed in version 1.23.2.","aliases":["GHSA-g89c-p67h-r497"],"modified":"2026-09-20T08:13:46.654569Z","published":"2026-09-18T15:55:46.914Z","related":["openSUSE-SU-2026:11719-1"],"database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-787"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/84xxx/CVE-2026-84383.json"},"references":[{"type":"WEB","url":"https://github.com/strukturag/libheif/releases/tag/v1.23.2"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/84xxx/CVE-2026-84383.json"},{"type":"ADVISORY","url":"https://github.com/strukturag/libheif/security/advisories/GHSA-g89c-p67h-r497"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-84383"},{"type":"FIX","url":"https://github.com/strukturag/libheif/commit/f4fb8bde4704ebb46e46ff9fb94407c9774153b2"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/strukturag/libheif","events":[{"introduced":"0c81a846b7401dbdb7118afd0761057f21e43511"},{"fixed":"f4fb8bde4704ebb46e46ff9fb94407c9774153b2"},{"fixed":"ac1cb05c39008f01525c991ff8b88f84ddf70fd2"}],"database_specific":{"extracted_events":[{"introduced":"1.22.0"},{"fixed":"1.23.2"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["v1.23.1","v1.23.0","v1.22.2","v1.22.1","v1.22.0"],"database_specific":{"vanir_signatures_modified":"2026-09-20T08:13:46Z","vanir_signatures":[{"signature_version":"v1","source":"https://github.com/strukturag/libheif/commit/f4fb8bde4704ebb46e46ff9fb94407c9774153b2","target":{"file":"libheif/image/pixelimage.cc","function":"HeifPixelImage::transfer_channel_from_image_as"},"deprecated":false,"digest":{"function_hash":"27639348516882446059066164186100437281","length":1139},"id":"CVE-2026-84383-02bdf1f1","signature_type":"Function"},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/strukturag/libheif/commit/f4fb8bde4704ebb46e46ff9fb94407c9774153b2","target":{"file":"libheif/image-items/image_item.cc","function":"ImageItem::decode_image"},"deprecated":false,"digest":{"function_hash":"44932082725045674601855282373196509579","length":6750},"id":"CVE-2026-84383-1cdeb368"},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/strukturag/libheif/commit/f4fb8bde4704ebb46e46ff9fb94407c9774153b2","target":{"file":"libheif/image/pixelimage.cc"},"deprecated":false,"digest":{"line_hashes":["217132304911219183479903804334915446555","258949591242235467401895887378115092748","240118561281792457164803687959715440156","167017913670170291985760958032267447205","229437723706466494319322918917015560144","116785358080287510192310986676860269425","306046843441618593032754641856618784625","317558342450283847968912453132683128976","3226524508160650319174364719195321107","190554417309520175018889644592549135104","308185993944005743541165050780656940121","248431936647841626512259120236788419486","17731495141506975014993664109702464295","47502196946950970722454877951807320304"],"threshold":0.9},"id":"CVE-2026-84383-2bf555dc"},{"deprecated":false,"digest":{"line_hashes":["51165288196829943724423022408366674139","195915446676683422062514205174315583766","234217406970474830290425054877937876352","15024544347873190833556990253260389051"],"threshold":0.9},"id":"CVE-2026-84383-5c1044d8","signature_type":"Line","signature_version":"v1","source":"https://github.com/strukturag/libheif/commit/f4fb8bde4704ebb46e46ff9fb94407c9774153b2","target":{"file":"libheif/image-items/image_item.cc"}},{"digest":{"function_hash":"114293617426658150862044387298809864254","length":3116},"id":"CVE-2026-84383-a3237714","signature_type":"Function","signature_version":"v1","source":"https://github.com/strukturag/libheif/commit/f4fb8bde4704ebb46e46ff9fb94407c9774153b2","target":{"file":"libheif/sequences/track_visual.cc","function":"Track_Visual::decode_next_image_sample"},"deprecated":false},{"digest":{"line_hashes":["58906645984302532908971020562056347881","81848429324747070148911760494294623056","321539262529097239856040407035050949145","272016937415841356836434509545492408987"],"threshold":0.9},"id":"CVE-2026-84383-de967bd4","signature_type":"Line","signature_version":"v1","source":"https://github.com/strukturag/libheif/commit/f4fb8bde4704ebb46e46ff9fb94407c9774153b2","target":{"file":"libheif/sequences/track_visual.cc"},"deprecated":false},{"signature_version":"v1","source":"https://github.com/strukturag/libheif/commit/f4fb8bde4704ebb46e46ff9fb94407c9774153b2","target":{"file":"libheif/image/pixelimage.cc","function":"HeifPixelImage::overlay"},"deprecated":false,"digest":{"function_hash":"207596382827640929986422787315333855365","length":2317},"id":"CVE-2026-84383-eb22a4b0","signature_type":"Function"},{"deprecated":false,"digest":{"line_hashes":["104077679788194899319035466314396756253","185422542825105166460370324787504025500","305389098078234417312617139370914672161","5232802758071402151399862401384013287"],"threshold":0.9},"id":"CVE-2026-84383-fd2d9cae","signature_type":"Line","signature_version":"v1","source":"https://github.com/strukturag/libheif/commit/f4fb8bde4704ebb46e46ff9fb94407c9774153b2","target":{"file":"libheif/image/pixelimage.h"}}],"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-84383.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}