Libheif · Libheif · CVE-2025-43967
**Name of the Vulnerable Software and Affected Versions**
libheif versions prior to 1.19.6
**Description**
The issue is caused by a NULL pointer dereference in `ImageItem Grid::get decoder` in `image-items/grid.cc`, which occurs when a grid image references a nonexistent image item.
**Recommendations**
For versions prior to 1.19.6, update to version 1.19.6 or later to resolve the issue.
As a temporary workaround, consider restricting the use of grid images that reference nonexistent image items until a patch is available.