Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-54240— libde265: Pixel accessor signed integer overflow causes heap OOB read/write

Quick assessment

Affected
strukturag libde265
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

libde265 是 H.265(HEVC)视频编解码器的一个开源实现。在 1.1.1 之前的版本中,使用有符号 32 位算术运算来计算像素偏移量。攻击者可以通过构造具有超大图像尺寸的 HEVC 视频流,触发整数溢出,从而导致越界的堆内存读取或写入。这可能导致数据泄露、内存损坏或解码器崩溃。该漏洞已在版本 1.1.1 中通过补丁修复。

CVSS 7.4 · High EPSS 0.24% · P15

Affected Version Matrix 1

VendorProduct Version RangeStatus
strukturag libde265 < 1.1.1 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-54240

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
libde265: Pixel accessor signed integer overflow causes heap OOB read/write
Source: CVE Program / CVE List V5
Vulnerability Description
libde265 is an open source implementation of the h.265 video codec. Versions prior to 1.1.1 use signed 32-bit arithmetic to calculate pixel offsets, allowing a crafted HEVC stream with large image dimensions to trigger an integer overflow and cause out-of-bounds heap reads or writes, potentially disclosing data, corrupting memory, or crashing the decoder. Version 1.1.1 contains a patch.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
整数溢出或超界折返
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
strukturag libde265 < 1.1.1 -

II. Public POCs for CVE-2026-54240

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-54240

登录查看更多情报信息。

Vendor Advisories for CVE-2026-54240 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-54240

No comments yet


Leave a comment