PT-2026-57347 · Libde265+3 · Libde265+3
CVE-2026-45382
·
Published
2026-05-19
·
Updated
2026-08-25
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
libde265 versions prior to 1.0.19
Description
An issue exists in the
decoder context::decode slice unit tiles() function where the software reads pps.CtbAddrRStoTS[ctbAddrRS] without validating the result against the size of the array. A malformed Picture Parameter Set (PPS) that encodes geometry inconsistent with the Sequence Parameter Set (SPS) can cause the ctbAddrRS variable to point outside the allocated memory, resulting in a 4-byte heap-buffer-overflow READ. A heap-buffer-overflow occurs when a program reads or writes data beyond the boundaries of a buffer allocated on the heap.Recommendations
Update to version 1.0.19.
Exploit
Fix
DoS
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linuxmint
Red Os
Ubuntu
Libde265