In Libheif 1.17.6, insufficient checks in ImageOverlay::parse() decoding a heif file containing an overlay image with forged offsets can lead to an out-of-bounds read and write.
| Software | From | Fixed in |
|---|---|---|
| struktur / libheif | 1.17.6 | 1.17.6.x |
| debian / debian_linux | 11.0 | 11.0.x |