CVE-2026-84383 is a heap out-of-bounds write in libheif versions 1.22.0 through 1.23.1. A crafted HEIF, HEIC, or AVIF item graph using nested iden and auxl references can cause duplicate Alpha planes with different bit depths to be added to image storage. During nearest-neighbor scaling, libheif allocates the destination Alpha plane according to an 8-bit plane, then can write 16-bit samples from a later 10-bit or 12-bit Alpha component into that allocation. The output geometry influences the overflow extent and encoded sample values influence the overwritten data.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This 17-file repository is a Docker-based, marker-only end-to-end exploit lab for CVE-2026-84383/GHSA-g89c-p67h-r497 in libheif 1.23.1. Its central executable workflow is scripts/verify.sh, supported by Bash preflight and ImageMagick wrapper scripts, three Dockerfiles, and Compose configurations. The repository builds an internal-only Discourse, PostgreSQL, and Redis environment; no host port is published. It submits a crafted HEIC file through the real authenticated POST /uploads.json route, causing Discourse UploadCreator to invoke ImageMagick and its HEIF delegate. The documented chain is a nested auxiliary-image decoding corruption, deterministic freed-object reuse, a file-controlled libjpeg callback, stack pivot, and fixed marker-writing ROP chain. The exploit fixture itself is referenced under fixtures/ and integrity-checked, but its binary contents are not included in the supplied file listing. Dockerfile.noaslr and scripts/magick-noaslr-wrapper intentionally preload jemalloc and disable ASLR only for the ImageMagick child; the Compose overlay additionally removes Docker seccomp restrictions needed by setarch. Therefore this is a valid but operationally constrained RCE proof, not evidence of ASLR-bypassing exploitation in a standard deployment. Dockerfile.patched builds libheif 1.23.2, and verify.sh demonstrates a differential result: exploit uploads produce the UID-1000 marker twice on 1.23.1, while 1.23.2 returns HTTP 422 without a marker; a benign HEIC still converts to JPEG on the patched image. Cleanup removes temporary API keys, staged data, markers, containers, and volumes.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A heap buffer overflow in libheif's scale_nearest_neighbor() processing of crafted nested image items.
A critical, remotely triggerable heap out-of-bounds write (CWE-787) in libheif versions 1.22.0 through before 1.23.2. Malicious HEIF, HEIC, or AVIF files with nested item-graph references can create duplicate Alpha planes with mismatched bit depths, causing 16-bit samples to be written into an allocation sized for an 8-bit Alpha plane. The stated CVSS v3.1 vector is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.
A high-severity vulnerability affecting Struktur libheif. The supplied CVSS v3.0 vector is CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, indicating a network-reachable issue with low attack complexity, no privileges or user interaction required, and high confidentiality, integrity, and availability impact.
A critical upstream libheif vulnerability that can potentially result in remote code execution on glibc-based Linux under certain conditions when untrusted image input is processed through sharp.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.