Description
libde265 is an open source implementation of the h.265 video codec. Versions prior to 1.1.1 use signed 32-bit arithmetic to calculate the sample adaptive offset input-buffer size, allowing a crafted HEVC stream with large dimensions and 16-bit luma samples to cause an integer overflow, an undersized allocation, and an out-of-bounds heap read that may expose heap data in decoded output or crash the decoder. Version 1.1.1 contains a patch.
Published: 2026-09-11
Score: 7.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Uncontrolled heap read or crash
Action: Apply Patch
AI Analysis

Impact

libde265 is an open source implementation of the H.265 video codec. In versions prior to 1.1.1, the decoder uses signed 32‑bit arithmetic to compute the sample adaptive offset input‑buffer size for the SAO sequential filter. A crafted HEVC stream containing large spatial dimensions and 16‑bit luma samples can trigger an integer overflow, resulting in an undersized allocation and an out‑of‑bounds heap read. The overflow may expose sensitive heap data in the decoded output, or it may lead to a decoder crash, causing informational disclosure or denial of service.

Affected Systems

The vulnerability affects the libde265 codec library distributed by strukturag. All releases earlier than 1.1.1 are vulnerable; version 1. Systems that use libde265 for video decoding, such as media players, streaming servers, or embedded devices, could be impacted if they process malicious HEVC streams.

Risk and Exploitability

With a CVSS score of 7.4 the flaw is considered moderate to high. The EPSS score of less than 1% indicates a low likelihood of public exploitation at present. The vulnerability is not listed in the CISA KEV catalog. The most likely attack vector is through the delivery of a malicious HEVC bitstream that satisfies the overflow conditions; no public exploit is known, but the lack of input validation makes the flaw a straightforward path for an attacker. If exploited successfully, the attacker could read arbitrary heap memory or trigger a crash, resulting in information disclosure or a denial‑of‑service condition libde265.

Generated by OpenCVE AI on September 15, 2026 at 20:56 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade libde265 to version 1.1.1 or later.
  • Configure the decoder to reject any HEVC streams with spatial dimensions or luma sample depth that exceed safe limits (e.g., 4096×4096 and 8‑bit).
  • If upgrading is not immediately possible, validate the HEVC stream header before decoding and reject headers that indicate large dimensions or 16‑bit path.

Generated by OpenCVE AI on September 15, 2026 at 20:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4789-1 libde265 security update
Debian DSA Debian DSA DSA-6413-1 libde265 security update
Ubuntu USN Ubuntu USN USN-8573-1 libde265 vulnerabilities
History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Struktur
Struktur libde265
Vendors & Products Struktur
Struktur libde265

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description libde265 is an open source implementation of the h.265 video codec. Versions prior to 1.1.1 use signed 32-bit arithmetic to calculate the sample adaptive offset input-buffer size, allowing a crafted HEVC stream with large dimensions and 16-bit luma samples to cause an integer overflow, an undersized allocation, and an out-of-bounds heap read that may expose heap data in decoded output or crash the decoder. Version 1.1.1 contains a patch.
Title libde265: SAO sequential filter heap buffer overflow via signed integer overflow
Weaknesses CWE-122
CWE-190
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H'}


Subscriptions

Struktur Libde265
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-14T16:15:30.052Z

Reserved: 2026-06-12T16:25:43.084Z

Link: CVE-2026-54241

cve-icon Vulnrichment

Updated: 2026-09-14T16:15:24.563Z

cve-icon NVD

Status : Deferred

Published: 2026-09-11T22:16:38.223

Modified: 2026-09-30T19:57:08.043

Link: CVE-2026-54241

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T21:00:17Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow

  • CWE-190

    Integer Overflow or Wraparound