Integer Overflow in h.265 Video Codec of libde265
CVE-2026-54241

7.4HIGH

Key Information:

Vendor

Strukturag

Status
Vendor
CVE Published:
11 September 2026

What is CVE-2026-54241?

The libde265 library, an open-source implementation of the h.265 video codec, has a vulnerability that stems from the use of signed 32-bit arithmetic for calculating the input-buffer size for sample adaptive offsets. This flaw allows an attacker to exploit a crafted HEVC stream containing large dimensions and 16-bit luma samples, potentially leading to an integer overflow. The consequence of this overflow can result in an undersized memory allocation, which may enable out-of-bounds heap reads. Such incidents could expose sensitive heap data in the output of decoded video streams or may lead to crashes of the decoder itself. Version 1.1.1 of libde265 has addressed this issue with a security patch.

Affected Version(s)

libde265 < 1.1.1

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.