ELA-1828-1 libde265 security update

multiple vulnerabilities

2026-09-20
Packagelibde265
Version1.0.11-0+deb9u8 (stretch), 1.0.11-0+deb10u8 (buster), 1.0.11-0+deb11u5 (bullseye)
Related CVEs CVE-2024-38949 CVE-2024-38950 CVE-2026-45382 CVE-2026-45383 CVE-2026-49295 CVE-2026-49337 CVE-2026-49346 CVE-2026-54240 CVE-2026-54241 TEMP-0000000-BB5891 TEMP-0000000-E66AA0


Multiple issues were found in libde265, an open source implementation of the H.265 video codec, which potentially may result in denial of service, heap/buffer overflows, information disclosure or code execution or have unspecified other impact.

CVE-2024-38949

Heap Buffer Overflow vulnerability allows attackers to crash the application via crafted payload.

CVE-2024-38950

Heap Buffer Overflow vulnerability allows attackers to crash the application via crafted payload.

CVE-2026-45382

Heap-buffer-overflow READ in decode_slice_unit_tiles via unvalidated PPS tile geometry.

CVE-2026-45383

Heap buffer overflow (OOB read) in decode_slice_unit_WPP() via out-of-bounds CtbAddrRStoTS access.

CVE-2026-49295

Out-of-bounds write in process_reference_picture_set via predicted short-term RPS.

CVE-2026-49337

Unbounded memory accumulation via orphaned slice headers in `read_slice_NAL`

CVE-2026-49346

Heap buffer overflow in de265_image_get_buffer via SPS dimension integer overflow

CVE-2026-54240

Pixel accessor signed integer overflow causes heap OOB read/write

CVE-2026-54241

SAO sequential filter heap buffer overflow via signed integer overflow

Two additional vulnerabilities for which CVE IDs are not yet available have been fixed. (The identifier in brackets is the GitHub identifier):

TEMP-0000000-BB5891 (GHSA-xp3h-6f5r-8cxp)

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') and Use After Free and Double Free 

TEMP-0000000-E66AA0 (GHSA-mm7m-v26f-wf8x)

heap-use-after-free in decoder_context::reset() via dangling previous_slice_header 


For Debian 10 buster, these problems have been fixed in version 1.0.11-0+deb10u8.

For Debian 11 bullseye, these problems have been fixed in version 1.0.11-0+deb11u5.

For Debian 9 stretch, these problems have been fixed in version 1.0.11-0+deb9u8.

We recommend that you upgrade your libde265 packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.