PT-2026-51028 · Libde265+3 · Libde265+3

·

CVE-2026-49346

·

Published

2026-06-19

·

Updated

2026-08-25

CVSS v2.0

8.5

High

VectorAV:N/AC:L/Au:N/C:N/I:P/A:C
Name of the Vulnerable Software and Affected Versions libde265 versions prior to 1.1.0
Description An issue exists in the h.265 video codec implementation where a crafted H.265 bitstream containing large SPS dimensions and 16-bit bit depth triggers a signed integer overflow in the de265 image get buffer() function. This overflow results in the plane allocation size being wrapped to a small value of approximately 1 KB. Subsequently, the fill image() function calculates the actual size using size t, leading to approximately 4 GB of data being written into the undersized heap buffer, which can cause a denial of service.
Recommendations Update to version 1.1.0.

Exploit

Fix

DoS

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-13664
CVE-2026-49346
ECHO-7756-D9D5-6FC4
GHSA-VV8H-932H-7R86
USN-8573-1

Affected Products

Linuxmint
Red Os
Ubuntu
Libde265