Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-6413-1 | libde265 security update |
Ubuntu USN |
USN-8573-1 | libde265 vulnerabilities |
Fri, 11 Sep 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | libde265 is an open source implementation of the h.265 video codec. Versions prior to 1.1.1 use signed 32-bit arithmetic to calculate the sample adaptive offset input-buffer size, allowing a crafted HEVC stream with large dimensions and 16-bit luma samples to cause an integer overflow, an undersized allocation, and an out-of-bounds heap read that may expose heap data in decoded output or crash the decoder. Version 1.1.1 contains a patch. | |
| Title | libde265: SAO sequential filter heap buffer overflow via signed integer overflow | |
| Weaknesses | CWE-122 CWE-190 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-11T21:21:59.190Z
Reserved: 2026-06-12T16:25:43.084Z
Link: CVE-2026-54241
No data.
Status : Received
Published: 2026-09-11T22:16:38.223
Modified: 2026-09-11T22:16:38.223
Link: CVE-2026-54241
No data.
OpenCVE Enrichment
Updated: 2026-09-12T06:15:04Z

Debian DSA
Ubuntu USN