LIBHEIF-0009
low harness-verifiedVVC decode glue: reachable assert(false) in parse_sps_for_vvcC_configuration on crafted SPS (gci/subpic TODO paths)
Full technical details — the precise location, reproduction, proof-of-concept and the write-up — are withheld until this finding is publicly disclosed in coordination with the upstream maintainers. The classification below is published; the rest will appear here once the advisory is live.
Classification
| Target | libheif |
|---|---|
| Area | Codec decode glue |
| Vuln class | dos |
| Severity | low |
| Status | harness-verified |
| Discovered | 2026-06-21 |