Advisories » MGASA-2026-0420

Updated libde265 package fixes security vulnerabilities

Publication date: 20 Sep 2026
Modification date: 20 Sep 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2024-38949 , CVE-2024-38950 , CVE-2025-61147 , CVE-2026-33164 , CVE-2026-33165 , CVE-2026-45382 , CVE-2026-45383 , CVE-2026-49295 , CVE-2026-49337 , CVE-2026-49346 , CVE-2026-54240 , CVE-2026-54241

Description

Heap Buffer Overflow vulnerability in Libde265 v1.0.15 allows attackers
to crash the application via crafted payload to display444as420 function
at sdl.cc. (CVE-2024-38949)
Heap Buffer Overflow vulnerability in Libde265 v1.0.15 allows attackers
to crash the application via crafted payload to __interceptor_memcpy
function. (CVE-2024-38950)
strukturag libde265 commit d9fea9d wa discovered to contain a
segmentation fault via the component
decoder_context::compute_framedrop_table(). (CVE-2025-61147)
NULL Pointer Dereference in libde265. (CVE-2026-33164)
Heap out-of-bounds write in libde265 1.0.16. (CVE-2026-33165)
libde265 has a heap-buffer-overflow READ in decode_slice_unit_tiles via
unvalidated PPS tile geometry. (CVE-2026-45382)
libde265 has a heap buffer overflow (OOB read) in
decode_slice_unit_WPP() via out-of-bounds CtbAddrRStoTS access —
libde265 <= v1.0.18. (CVE-2026-45383)
libde265 has an out-of-bounds write in process_reference_picture_set via
predicted short-term RPS. (CVE-2026-49295)
libde265 has an unbounded memory leak via orphaned slice headers in
`read_slice_NAL`. (CVE-2026-49337)
libde265 has a heap buffer overflow in de265_image_get_buffer via SPS
dimension integer overflow. (CVE-2026-49346)
Pixel accessor signed integer overflow causes heap OOB read/write.
(CVE-2026-54240)
SAO sequential filter heap buffer overflow via signed integer overflow.
(CVE-2026-54241)
                

References

SRPMS

10/core

10/tainted