Out-of-bounds read in libde265 - CVE-2026-45382
Published: May 19, 2026
libde265
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in decoder_context::decode_slice_unit_tiles when processing malformed PPS tile geometry inconsistent with the SPS. A remote attacker can supply specially crafted slice and PPS NAL content to cause a denial of service.
Worker threads must be enabled, and the issue is triggered on the parallel multi-tile decode path with a slice header containing one or more entry point offsets.