Libheif · Libheif · CVE-2025-43966
**Name of the Vulnerable Software and Affected Versions**
libheif versions prior to 1.19.6
**Description**
The issue is related to a NULL pointer dereference in the `ImageItem iden` function, located in `image-items/iden.cc`. This problem can lead to potential crashes or other unintended behavior when the function is called.
**Recommendations**
For versions prior to 1.19.6, update to version 1.19.6 or later to resolve the issue. As a temporary workaround, consider restricting access to the `ImageItem iden` function in `image-items/iden.cc` until a patch is available.