CVE-2025-43966: Null Pointer Dereference
Published Apr 20, 2025
·Updated
libheif before 1.19.6 has a NULL pointer dereference in ImageItemiden in image-items/iden.cc.
Affected Software
2 affected components
Johan Levin libheif<1.19.6
struktur Libheif<1.19.6
Remediation
Event History
Apr 20, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Apr 17, 57340
Event
via FIRST·01:40 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-43966?
CVE-2025-43966 has a severity rating that indicates it may lead to application crashes due to a NULL pointer dereference.
2
How do I fix CVE-2025-43966?
To fix CVE-2025-43966, upgrade libheif to version 1.19.6 or later.
3
What software is affected by CVE-2025-43966?
CVE-2025-43966 affects libheif versions prior to 1.19.6.
4
What are the potential impacts of CVE-2025-43966?
The potential impacts of CVE-2025-43966 include application instability and crashes when handling specific image items.
5
Is CVE-2025-43966 related to any specific functions in libheif?
Yes, CVE-2025-43966 is related to a NULL pointer dereference in the ImageItem_iden function in image-items/iden.cc.