Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-54241— libde265: SAO sequential filter heap buffer overflow via signed integer overflow

Quick assessment

Affected
strukturag libde265
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

libde265 是 H.265 视频编解码器的一个开源实现。在 1.1.1 之前的版本中,使用有符号 32 位算术运算来计算采样自适应偏移(Sample Adaptive Offset, SAO)输入缓冲区大小。攻击者可以构造具有超大分辨率且包含 16 位亮度(luma)采样的 HEVC 码流,从而引发整数溢出、缓冲区分配过小以及堆越界读(out-of-bounds heap read),可能导致堆内存数据泄露到解码输出中,或导致解码器崩溃。该问题已在 1.1.1 版本中通过补丁修复。

CVSS 7.4 · High EPSS 0.24% · P15

Affected Version Matrix 1

VendorProduct Version RangeStatus
strukturag libde265 < 1.1.1 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-54241

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
libde265: SAO sequential filter heap buffer overflow via signed integer overflow
Source: CVE Program / CVE List V5
Vulnerability Description
libde265 is an open source implementation of the h.265 video codec. Versions prior to 1.1.1 use signed 32-bit arithmetic to calculate the sample adaptive offset input-buffer size, allowing a crafted HEVC stream with large dimensions and 16-bit luma samples to cause an integer overflow, an undersized allocation, and an out-of-bounds heap read that may expose heap data in decoded output or crash the decoder. Version 1.1.1 contains a patch.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
堆缓冲区溢出
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
strukturag libde265 < 1.1.1 -

II. Public POCs for CVE-2026-54241

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-54241

登录查看更多情报信息。

Vendor Advisories for CVE-2026-54241 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-54241

No comments yet


Leave a comment