PT-2026-57347 · Libde265+3 · Libde265+3

CVE-2026-45382

·

Published

2026-05-19

·

Updated

2026-08-25

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions libde265 versions prior to 1.0.19
Description An issue exists in the decoder context::decode slice unit tiles() function where the software reads pps.CtbAddrRStoTS[ctbAddrRS] without validating the result against the size of the array. A malformed Picture Parameter Set (PPS) that encodes geometry inconsistent with the Sequence Parameter Set (SPS) can cause the ctbAddrRS variable to point outside the allocated memory, resulting in a 4-byte heap-buffer-overflow READ. A heap-buffer-overflow occurs when a program reads or writes data beyond the boundaries of a buffer allocated on the heap.
Recommendations Update to version 1.0.19.

Exploit

Fix

DoS

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-14526
CVE-2026-45382
ECHO-6D7B-247D-24F3
GHSA-HWHX-X2MQ-CCR9
USN-8573-1

Affected Products

Linuxmint
Red Os
Ubuntu
Libde265