Impact
libde265 implements the H.265 video codec. In versions prior to 1.1.1, signed 32‑bit arithmetic is used to calculate pixel offsets, which can overflow when a crafted HEVC stream contains very large image dimensions. The resulting integer overflow is a CWE‑190 weakness and can lead to out‑of‑bounds heap reads or writes, a CWE‑787 memory, or crash the decoder, thereby compromising confidentiality and integrity.
Affected Systems
strukturAG’s libde265 library is affected. All releases prior to 1.1.1; version 1.1.1 contains the fix.
Risk and Exploitability
The CVSS base score of 7.4 and EPSS score of <1% indicate a medium‑severe risk but a very low probability of exploitation, and it is not listed in CISA KEV. Based on the description, it is inferred that an attacker must deliver a malicious HEVC stream to a program that links against the vulnerable library. The overflow may allow out‑of‑bounds reads or writes, potentially exposing confidential data or corrupting memory, which can lead to application crashes. No public exploit is currently recorded, so the risk remains theoretical but warrants immediate attention for security‑critical deployments.
OpenCVE Enrichment
Debian DLA
Debian DSA
Ubuntu USN