Junglewise Threat Intelligence

CVE-2026-45383: Strukturag libde265 heap buffer overflow in decode_slice_unit_WPP

CVE-2026-45383 · Severity: info · CVSS 6.9 · Published 2026-07-21

Technologies: struktur AG Libde265. Vendors: Strukturag, struktur AG.

Executive brief

libde265 is an open-source library used to decode H.265 (HEVC) video files, commonly found in image viewers and media players. A flaw in how the library handles specific video headers allows a specially crafted video or image file to cause the application to read memory outside of its intended boundaries. This can lead to application crashes or the potential exposure of sensitive information from the computer's memory.

Technical details

A heap-based out-of-bounds read exists in the `decoder_context::decode_slice_unit_WPP()` function within `libde265/decctx.cc`. The vulnerability is triggered when decoding a Wavefront Parallel Processing (WPP) HEVC slice where crafted PPS/SPS headers cause the calculated `ctbAddrRS` index to exceed the bounds of the `pps.CtbAddrRStoTS` vector. An attacker can exploit this by providing a malicious HEVC/HEIF file, leading to an out-of-bounds read of adjacent heap memory. This can result in information disclosure or application instability. The issue is fixed in version 1.0.19.

Affected products

  • strukturag libde265 < 1.0.19

Timeline

  • 2026-03-27: other: Vulnerability confirmed present in master branch
  • 2026-05-19: advisory: GitHub Security Advisory published
  • 2026-07-21: disclosed: CVE published to NVD

References

Related threats