Integer Overflow Vulnerability in libde265 Video Codec by Struktur AG
CVE-2026-54240

7.4HIGH

Key Information:

Vendor

Strukturag

Status
Vendor
CVE Published:
11 September 2026

What is CVE-2026-54240?

libde265, an open-source implementation of the H.265 video codec, is susceptible to an integer overflow vulnerability due to the use of signed 32-bit arithmetic for pixel offset calculations. Attackers can craft malicious HEVC streams that leverage large image dimensions to trigger the vulnerability. This flaw permits out-of-bounds heap reads or writes, which could lead to potential data disclosure, memory corruption, or decoder crashes. Users are urged to update to version 1.1.1, which includes a patch for this vulnerability.

Affected Version(s)

libde265 < 1.1.1

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.