-------------------------------------------------------------------------
Debian LTS Advisory DLA-4789-1                [email protected]
https://www.debian.org/lts/security/                         Tobias Frost
September 20, 2026                            https://wiki.debian.org/LTS
-------------------------------------------------------------------------

Package        : libde265
Version        : 1.0.11-1+deb12u3
CVE ID         : CVE-2023-51792 CVE-2024-38949 CVE-2024-38950 CVE-2026-33164 
                 CVE-2026-33165 CVE-2026-45382 CVE-2026-45383 CVE-2026-49295 
                 CVE-2026-49337 CVE-2026-49346 CVE-2026-54240 CVE-2026-54241
Debian Bug     : 1074416 1131468 1131469 1140431

Multiple issues were found in libde265, an open source implementation of
the H.265 video codec, which potentially may result in denial of
service, heap/buffer overflows, information disclosure or code
execution or have unspecified other impact.

CVE-2023-51792

    Buffer Overflow vulnerability allows a local attacker to cause a
    denial of service via the allocation size exceeding the maximum
    supported size of 0x10000000000.

CVE-2024-38949

    Heap Buffer Overflow vulnerability allows attackers to crash the
    application via crafted payload.

CVE-2024-38950

    Heap Buffer Overflow vulnerability allows attackers to crash the
    application via crafted payload.

CVE-2026-33164

    A malformed H.265 PPS NAL unit causes a segmentation fault.

CVE-2026-33165

    A crafted HEVC bitstream causes an out-of-bounds heap write.

CVE-2026-45382

    Heap-buffer-overflow READ in decode_slice_unit_tiles via unvalidated
    PPS tile geometry.

CVE-2026-45383

    Heap buffer overflow (OOB read) in decode_slice_unit_WPP() via
    out-of-bounds CtbAddrRStoTS access.

CVE-2026-49295

    Out-of-bounds write in process_reference_picture_set via predicted
    short-term RPS.

CVE-2026-49337

    Unbounded memory accumulation via orphaned slice headers in
    `read_slice_NAL`

CVE-2026-49346

    Heap buffer overflow in de265_image_get_buffer via SPS dimension
    integer overflow

CVE-2026-54240

    Pixel accessor signed integer overflow causes heap OOB read/write

CVE-2026-54241

    SAO sequential filter heap buffer overflow via signed integer
    overflow


Two additional vulnerabilities for which CVE IDs are not yet available
have been fixed. (The identifier in brackets is the GitHub identifier):

CVE-2026-XXXX (GHSA-xp3h-6f5r-8cxp)

    Concurrent Execution using Shared Resource with Improper
    Synchronization ('Race Condition') and Use After Free and Double Free 

CVE-2026-XXXX (GHSA-mm7m-v26f-wf8x)

    heap-use-after-free in decoder_context::reset() via dangling
    previous_slice_header 


For Debian 12 bookworm, these problems have been fixed in version
1.0.11-1+deb12u3.

We recommend that you upgrade your libde265 packages.

For the detailed security status of libde265 please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/libde265

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

Attachment: signature.asc
Description: PGP signature

Reply via email to