Researcher weaponizes libheif 1-day into full RCE via UAF and tcache poisoning
dyn___ · x · 2026-09-23
After Hacktron's libheif-based pwn of OpenAI, researcher kmkzsecurity found an undocumented remote primitive in libheif 1.23.x behind an image API: attacker-controlled iref/dimg reference graphs produce repeatable malloc(16) allocations in glibc's 0x20 class, enabling remote heap grooming.
When a fresh libheif 1-day with no public PoC dropped, he built a full chain from the source diff: TAI use-after-free → reclaim → stale free → safe-linked tcache poison → ZdlPvm GOT hijack → system() → RCE.
The underlying bug is GHSA-qwpf-5wf7-r996: a shallow-copied mtaitimestamp raw pointer causes use-after-free and double free, affecting libheif 1.21.0–1.23.4, patched in 1.23.5, found by Tencent's Yunding Lab. No PoC was published.
More from Safety
- Academics clash over invoking 'disinformation' to justify policing AI use in the classroom — sethlazar · 2026-09-23
- Critical Next.js RCE: CVE-2026-94545 hits next/og ImageResponse via Satori SVG escaping flaw — evilsocket · 2026-09-23
- Ethan Mollick: has a frontier model actually caused a major security incident in normal deployment? — emollick · 2026-09-23
- Pangram AI detector under fire: removing line breaks triggers false positives on human writing — JFPuget · 2026-09-23
- Palo Alto launches agentic AI defense subscription with gated Claude and GPT models — brucemacv · 2026-09-23
- Europe's six AI stack risks: from declining income to strategic irrelevance — ohlennart · 2026-09-23