| Package | libde265 |
|---|---|
| Version | 1.0.11-0+deb9u8 (stretch), 1.0.11-0+deb10u8 (buster), 1.0.11-0+deb11u5 (bullseye) |
| Related CVEs | CVE-2024-38949 CVE-2024-38950 CVE-2026-45382 CVE-2026-45383 CVE-2026-49295 CVE-2026-49337 CVE-2026-49346 CVE-2026-54240 CVE-2026-54241 TEMP-0000000-BB5891 TEMP-0000000-E66AA0 |
Multiple issues were found in libde265, an open source implementation of the H.265 video codec, which potentially may result in denial of service, heap/buffer overflows, information disclosure or code execution or have unspecified other impact.
CVE-2024-38949
Heap Buffer Overflow vulnerability allows attackers to crash the application via crafted payload.
CVE-2024-38950
Heap Buffer Overflow vulnerability allows attackers to crash the application via crafted payload.
CVE-2026-45382
Heap-buffer-overflow READ in decode_slice_unit_tiles via unvalidated PPS tile geometry.
CVE-2026-45383
Heap buffer overflow (OOB read) in decode_slice_unit_WPP() via out-of-bounds CtbAddrRStoTS access.
CVE-2026-49295
Out-of-bounds write in process_reference_picture_set via predicted short-term RPS.
CVE-2026-49337
Unbounded memory accumulation via orphaned slice headers in `read_slice_NAL`
CVE-2026-49346
Heap buffer overflow in de265_image_get_buffer via SPS dimension integer overflow
CVE-2026-54240
Pixel accessor signed integer overflow causes heap OOB read/write
CVE-2026-54241
SAO sequential filter heap buffer overflow via signed integer overflow
Two additional vulnerabilities for which CVE IDs are not yet available have been fixed. (The identifier in brackets is the GitHub identifier):
TEMP-0000000-BB5891 (GHSA-xp3h-6f5r-8cxp)
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') and Use After Free and Double Free
TEMP-0000000-E66AA0 (GHSA-mm7m-v26f-wf8x)
heap-use-after-free in decoder_context::reset() via dangling previous_slice_header
For Debian 10 buster, these problems have been fixed in version 1.0.11-0+deb10u8.
For Debian 11 bullseye, these problems have been fixed in version 1.0.11-0+deb11u5.
For Debian 9 stretch, these problems have been fixed in version 1.0.11-0+deb9u8.
We recommend that you upgrade your libde265 packages.
Further information about Extended LTS security advisories can be found in the dedicated section of our website.