PT-2025-17423 · Libheif+2 · Libheif+2

Bobfriesenhahn

·

Published

2025-02-28

·

Updated

2025-04-21

·

CVE-2025-43967

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions libheif versions prior to 1.19.6
Description The issue is caused by a NULL pointer dereference in ImageItem Grid::get decoder in image-items/grid.cc, which occurs when a grid image references a nonexistent image item.
Recommendations For versions prior to 1.19.6, update to version 1.19.6 or later to resolve the issue. As a temporary workaround, consider restricting the use of grid images that reference nonexistent image items until a patch is available.

Exploit

Fix

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

BDU:2025-14110
CVE-2025-43967
ECHO-5F1C-C6A2-B5C3

Affected Products

Astra Linux
Debian
Libheif