CVE-2025-61147
published 2026-02-23CVE-2025-61147: strukturag libde265 commit d9fea9d wa discovered to contain a segmentation fault via the component decoder_context::compute_framedrop_table().
PriorityP420medium6.2CVSS 3.1
AVLACLPRNUINSUCNINAH
EPSS
0.16%
5.4th percentile
strukturag libde265 commit d9fea9d wa discovered to contain a segmentation fault via the component decoder_context::compute_framedrop_table().
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libde265 | < libde265 1.0.18-1 (forky) | libde265 1.0.18-1 (forky) |
| struktur | libde265 | < 1.0.17 | 1.0.17 |
| struktur | libde265 | >= 0 < 1.0.18-1 | 1.0.18-1 |
| ubuntu | libde265 | — | — |
CVSS provenance
nvdv3.16.2MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv6.2MEDIUM
vendor_debian6.2LOW
vendor_ubuntu3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
libde265 vulnerabilities
vendor_ubuntu·2026-07-20·CVSS 3.3
CVE-2026-45382 [LOW] libde265 vulnerabilities
Title: libde265 vulnerabilities
Summary: Several security issues were fixed in libde265.
It was discovered that libde265 did not properly manage memory under
certain circumstances. An attacker could possibly use this issue to
cause libde265 to crash, resulting in a denial of service. This issue
only affected Ubuntu 22.04 LTS. (CVE-2023-51792)
It was discovered that libde265 did not properly handle certain
malformed media files, leading to a heap buffer overflow. An attacker
could possibly use this issue to cause libde265 to crash, resulting in
a denial of service. (CVE-2024-38949, CVE-2024-38950)
It was discovered that libde265 did not properly handle certain
malformed input, leading to a segmentation fault. An attacker could
possibly use this issue to cause libde265 to crash, resultin
Debian
CVE-2025-61147: libde265 - strukturag libde265 commit d9fea9d wa discovered to contain a segmentation fault...
vendor_debian·2025·CVSS 6.2
CVE-2025-61147 [MEDIUM] CVE-2025-61147: libde265 - strukturag libde265 commit d9fea9d wa discovered to contain a segmentation fault...
strukturag libde265 commit d9fea9d wa discovered to contain a segmentation fault via the component decoder_context::compute_framedrop_table().
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 1.0.18-1)
sid: resolved (fixed in 1.0.18-1)
trixie: open
GHSA
GHSA-4phc-m7h5-frwr: strukturag libde265 commit d9fea9d wa discovered to contain a segmentation fault via the component decoder_context::compute_framedrop_table()
ghsa_unreviewed·2026-02-23
CVE-2025-61147 [MEDIUM] CWE-120 GHSA-4phc-m7h5-frwr: strukturag libde265 commit d9fea9d wa discovered to contain a segmentation fault via the component decoder_context::compute_framedrop_table()
strukturag libde265 commit d9fea9d wa discovered to contain a segmentation fault via the component decoder_context::compute_framedrop_table().
OSV
CVE-2025-61147: strukturag libde265 commit d9fea9d wa discovered to contain a segmentation fault via the component decoder_context::compute_framedrop_table()
osv·2026-02-23·CVSS 6.2
CVE-2025-61147 [MEDIUM] CVE-2025-61147: strukturag libde265 commit d9fea9d wa discovered to contain a segmentation fault via the component decoder_context::compute_framedrop_table()
strukturag libde265 commit d9fea9d wa discovered to contain a segmentation fault via the component decoder_context::compute_framedrop_table().
No detection rules found.
No public exploits indexed.
2026-02-23
Published