Heap Buffer Overflow in libde265 Video Codec Implementation
CVE-2026-45382
6.9MEDIUM
What is CVE-2026-45382?
A vulnerability exists in the libde265 video codec implementation where improper validation of PPS-supplied geometry against SPS can lead to a heap buffer overflow. This occurs when a malformed PPS allows access to memory beyond the allocated buffer, which could potentially be exploited by attackers to execute arbitrary code or crash the application. Version 1.0.19 resolves this issue by ensuring robust validation of the parameters before they are accessed.
Affected Version(s)
libde265 < 1.0.19
