libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.3, the no-icef full-item branch of unc_decoder::get_compressed_image_data_uncompressed() in libheif/codecs/uncompressed/unc_decoder.cc retains an addition-based range check that can wrap when a crafted uncompressed tile grid produces a large range_start_offset and range_size. The overflow makes the bounds comparison pass and allows heif_image_handle_decode_image_tile() to call memcpy() with an invalid source pointer and a very large length when decoding a valid high-index advertised tile. This incomplete remediation of CVE-2026-62292 can reliably crash tile-processing applications, while whole-image decoding is not claimed to reach the demonstrated path. This issue is fixed in version 1.23.3.
{
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-125"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/84xxx/CVE-2026-84451.json"
}"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-84451.json"
[
{
"deprecated": false,
"digest": {
"function_hash": "122515340523743000692419636798249179788",
"length": 2932
},
"id": "CVE-2026-84451-51ec2111",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/strukturag/libheif/commit/8bfed9a9ed008e4ef28abc736284a90d3cba754f",
"target": {
"file": "libheif/codecs/uncompressed/unc_decoder.cc",
"function": "unc_decoder::get_compressed_image_data_uncompressed"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"157773266475716883312276441226944622845",
"301697979167988542478748232332303574719",
"86520503334819419963639447664287200330",
"280614601139895828286494313771936772299"
],
"threshold": 0.9
},
"id": "CVE-2026-84451-d0bd9237",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/strukturag/libheif/commit/8bfed9a9ed008e4ef28abc736284a90d3cba754f",
"target": {
"file": "libheif/codecs/uncompressed/unc_decoder.cc"
}
}
]
"2026-09-20T08:13:44Z"