What is CVE-2026-45382?
CVE-2026-45382 is an out-of-bounds read vulnerability in `decoder_context::decode_slice_unit_tiles` of the libde265 H.265 codec implementation. It affects versions prior to 1.0.19, allowing a remote attacker to read sensitive data by manipulating PPS parameters. Users should upgrade to the latest version.
Azərbaycanca: CVE-2026-45382 libde265-in H.265 video codec implementasiyasında `decoder_context::decode_slice_unit_tiles` funksiyasında sərhəd xaricində oxuma (out-of-bounds read) zəifliyidir. 1.0.19 versiyasından əvvəlki versiyaları təsir edir, uzaqdan hücum edən şəxs PPS parametrləri ilə manipulyasiya edərək məlumat sızmasına səbəb ola bilər. libde265-i ən son versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-125
FAQ2
Which software component does CVE-2026-45382 affect?
This vulnerability exists in the `decoder_context::decode_slice_unit_tiles` function of libde265's H.265 codec implementation.
How can one mitigate CVE-2026-45382?
It is recommended to upgrade libde265 to version 1.0.19 or a later release.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.