cbcvebase.

Strukturag Libde265 vulnerabilities

7 known vulnerabilities affecting strukturag/libde265.

Total CVEs
7
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH3MEDIUM4

Vulnerabilities

Page 1 of 1
CVE-2026-45383P3MEDIUMCVSS 6.9fixed in 1.0.192026-07-21
CVE-2026-45383 [MEDIUM] CWE-125 CVE-2026-45383: libde265 is an open source implementation of the h.265 video codec. Versions prior to 1.0.19 have a libde265 is an open source implementation of the h.265 video codec. Versions prior to 1.0.19 have a heap buffer overflow (out-of-bounds READ) exists in `decoder_context::decode_slice_unit_WPP()` in `libde265/decctx.cc`. When decoding a WPP (Wavefront Parallel Processing) HEVC slice, `ctbAddrRS` is computed as `ctbRow * ctbsWidth` inside the entry-poi
nvd
CVE-2026-45382P3MEDIUMCVSS 6.9fixed in 1.0.192026-07-21
CVE-2026-45382 [MEDIUM] CWE-125 CVE-2026-45382: libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.19, `decode libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.19, `decoder_context::decode_slice_unit_tiles` (libde265/decctx.cc:920) reads `pps.CtbAddrRStoTS[ctbAddrRS]` at line 966 where `ctbAddrRS = ctbY * ctbsWidth + ctbX` is computed from PPS-supplied `colBd[]`/`rowBd[]` arrays without validating the result against `C
nvd
CVE-2026-33164P3HIGHCVSS 7.5fixed in 1.0.172026-03-20
CVE-2026-33164 [HIGH] CWE-122 CVE-2026-33164: libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.17, a malfo libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.17, a malformed H.265 PPS NAL unit causes a segmentation fault in pic_parameter_set::set_derived_values(). This issue has been patched in version 1.0.17.
nvd
CVE-2026-49295P3HIGHCVSS 7.1fixed in 1.0.202026-06-19
CVE-2026-49295 [HIGH] CWE-787 CVE-2026-49295: libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.20, a craft libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.20, a crafted H.265 bitstream can cause an out-of-bounds array write in `decoder_context::process_reference_picture_set()` (`libde265/decctx.cc:1376`). The root cause is a missing aggregate bound check on predicted short-term reference picture set entries. Individ
nvd
CVE-2026-49346P3HIGHCVSS 7.1fixed in 1.1.02026-06-19
CVE-2026-49346 [HIGH] CWE-190 CVE-2026-49346: libde265 is an open source implementation of the h.265 video codec. Prior to version 1.1.0, a crafte libde265 is an open source implementation of the h.265 video codec. Prior to version 1.1.0, a crafted H.265 bitstream with large SPS dimensions and 16-bit bit depth causes a signed integer overflow in `de265_image_get_buffer()` (`libde265/image.cc:128`). The overflow wraps the plane allocation size to a small value (~1 KB), but the subsequent `fill_im
nvd
CVE-2026-33165P4MEDIUMCVSS 5.0fixed in 1.0.172026-03-20
CVE-2026-33165 [MEDIUM] CWE-787 CVE-2026-33165: libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.17, a craft libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.17, a crafted HEVC bitstream causes an out-of-bounds heap write confirmed by AddressSanitizer. The trigger is a stale ctb_info.log2unitSize after an SPS change where PicWidthInCtbsY and PicHeightInCtbsY stay constant but Log2CtbSizeY changes, causing set_SliceHe
nvd
CVE-2026-49337P4MEDIUMCVSS 4.3fixed in 1.0.202026-06-19
CVE-2026-49337 [MEDIUM] CWE-770 CVE-2026-49337: libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.20, a craft libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.20, a crafted sequence of H.265 NAL units causes `decoder_context::read_slice_NAL()` (`libde265/decctx.cc:481`) to attach slice headers to a finished picture object that has no active image unit, resulting in attacker-controlled unbounded heap growth. The retain
nvd
Strukturag Libde265 vulnerabilities | cvebase