CVE-2025-43967
LowVulnerability Description
libheif before 1.19.6 has a NULL pointer dereference in ImageItem_Grid::get_decoder in image-items/grid.cc because a grid image can reference a nonexistent image item.
CVSS Metrics
Common Vulnerability Scoring System
Vector String:
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
Known Affected Software
44 configuration(s) from 1 vendor(s)
cpe:2.3:a:struktur:libheif:1.3.2:*:*:*:*:*:*:*
cpe:2.3:a:struktur:libheif:1.11.0:*:*:*:*:*:*:*
cpe:2.3:a:struktur:libheif:1.14.2:*:*:*:*:*:*:*
cpe:2.3:a:struktur:libheif:1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:struktur:libheif:1.16.1:*:*:*:*:*:*:*
cpe:2.3:a:struktur:libheif:1.19.5:*:*:*:*:*:*:*
cpe:2.3:a:struktur:libheif:1.17.2:*:*:*:*:*:*:*
cpe:2.3:a:struktur:libheif:1.9.0:*:*:*:*:*:*:*
cpe:2.3:a:struktur:libheif:1.15.2:*:*:*:*:*:*:*
cpe:2.3:a:struktur:libheif:1.3.1:*:*:*:*:*:*:*
cpe:2.3:a:struktur:libheif:1.2.0:*:*:*:*:*:*:*
cpe:2.3:a:struktur:libheif:1.6.2:*:*:*:*:*:*:*
cpe:2.3:a:struktur:libheif:1.10.0:*:*:*:*:*:*:*
cpe:2.3:a:struktur:libheif:1.17.3:*:*:*:*:*:*:*
cpe:2.3:a:struktur:libheif:1.19.0:*:*:*:*:*:*:*
cpe:2.3:a:struktur:libheif:1.18.1:*:*:*:*:*:*:*
cpe:2.3:a:struktur:libheif:1.15.1:*:*:*:*:*:*:*
cpe:2.3:a:struktur:libheif:1.14.1:*:*:*:*:*:*:*
cpe:2.3:a:struktur:libheif:1.16.0:*:*:*:*:*:*:*
cpe:2.3:a:struktur:libheif:1.8.0:*:*:*:*:*:*:*
cpe:2.3:a:struktur:libheif:1.13.0:*:*:*:*:*:*:*
cpe:2.3:a:struktur:libheif:1.18.2:*:*:*:*:*:*:*
cpe:2.3:a:struktur:libheif:1.19.3:*:*:*:*:*:*:*
cpe:2.3:a:struktur:libheif:1.6.0:*:*:*:*:*:*:*
cpe:2.3:a:struktur:libheif:1.12.0:*:*:*:*:*:*:*
cpe:2.3:a:struktur:libheif:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:struktur:libheif:1.5.0:*:*:*:*:*:*:*
cpe:2.3:a:struktur:libheif:1.17.0:*:*:*:*:*:*:*
cpe:2.3:a:struktur:libheif:1.19.2:*:*:*:*:*:*:*
cpe:2.3:a:struktur:libheif:1.18.0:-:*:*:*:*:*:*
cpe:2.3:a:struktur:libheif:1.17.6:*:*:*:*:*:*:*
cpe:2.3:a:struktur:libheif:1.14.0:*:*:*:*:*:*:*
cpe:2.3:a:struktur:libheif:1.5.1:*:*:*:*:*:*:*
cpe:2.3:a:struktur:libheif:1.3.0:*:*:*:*:*:*:*
cpe:2.3:a:struktur:libheif:1.6.1:*:*:*:*:*:*:*
cpe:2.3:a:struktur:libheif:1.17.5:*:*:*:*:*:*:*
cpe:2.3:a:struktur:libheif:1.1.0:*:*:*:*:*:*:*
cpe:2.3:a:struktur:libheif:1.19.4:*:*:*:*:*:*:*
cpe:2.3:a:struktur:libheif:1.9.1:*:*:*:*:*:*:*
cpe:2.3:a:struktur:libheif:1.15.0:*:*:*:*:*:*:*
cpe:2.3:a:struktur:libheif:1.17.4:*:*:*:*:*:*:*
cpe:2.3:a:struktur:libheif:1.17.1:*:*:*:*:*:*:*
cpe:2.3:a:struktur:libheif:1.16.2:*:*:*:*:*:*:*
cpe:2.3:a:struktur:libheif:1.19.1:*:*:*:*:*:*:*
CPUAPR2026
Oracle Critical Patch Update Advisory - April 2026
CPUJAN2026
Oracle Critical Patch Update Advisory - January 2026
CVE-2025-43967
CVE-2025-43967
References & Resources
Severity Details
Weakness Type (CWE)
NULL Pointer Dereference
- Description
- The product dereferences a pointer that it expects to be valid but is NULL.
- Exploit Likelihood
- Medium
- Typical Severity
- High
- Abstraction Level
- Base
Key Information
- Published Date
- April 21, 2025
