Impact
libde265 is an open source implementation of the H.265 video codec. In versions prior to 1.1.1, the decoder uses signed 32‑bit arithmetic to compute the sample adaptive offset input‑buffer size for the SAO sequential filter. A crafted HEVC stream containing large spatial dimensions and 16‑bit luma samples can trigger an integer overflow, resulting in an undersized allocation and an out‑of‑bounds heap read. The overflow may expose sensitive heap data in the decoded output, or it may lead to a decoder crash, causing informational disclosure or denial of service.
Affected Systems
The vulnerability affects the libde265 codec library distributed by strukturag. All releases earlier than 1.1.1 are vulnerable; version 1. Systems that use libde265 for video decoding, such as media players, streaming servers, or embedded devices, could be impacted if they process malicious HEVC streams.
Risk and Exploitability
With a CVSS score of 7.4 the flaw is considered moderate to high. The EPSS score of less than 1% indicates a low likelihood of public exploitation at present. The vulnerability is not listed in the CISA KEV catalog. The most likely attack vector is through the delivery of a malicious HEVC bitstream that satisfies the overflow conditions; no public exploit is known, but the lack of input validation makes the flaw a straightforward path for an attacker. If exploited successfully, the attacker could read arbitrary heap memory or trigger a crash, resulting in information disclosure or a denial‑of‑service condition libde265.
OpenCVE Enrichment
Debian DLA
Debian DSA
Ubuntu USN