Heap Buffer Overflow in libde265 Video Codec Implementation
CVE-2026-45382

6.9MEDIUM

Key Information:

Vendor

Strukturag

Status
Vendor
CVE Published:
21 July 2026

What is CVE-2026-45382?

A vulnerability exists in the libde265 video codec implementation where improper validation of PPS-supplied geometry against SPS can lead to a heap buffer overflow. This occurs when a malformed PPS allows access to memory beyond the allocated buffer, which could potentially be exploited by attackers to execute arbitrary code or crash the application. Version 1.0.19 resolves this issue by ensuring robust validation of the parameters before they are accessed.

Affected Version(s)

libde265 < 1.0.19

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.