Opened 4 months ago

Closed 4 months ago

#23323 closed enhancement (fixed)

libde265-1.0.19

Reported by: Bruce Dubbs Owned by: SecurityAdvisory
Priority: elevated Milestone: 13.1
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

New point version.

Change History (4)

comment:1 by Douglas R. Reno, 4 months ago

Priority: normal → elevated

This includes fixes for CVE-2026-45382 and CVE-2026-45383. Both are rated as Medium so promoting to Elevated.

comment:2 by Joe Locash, 4 months ago

Owner: changed from blfs-book to Joe Locash
Status: new → assigned

comment:3 by Joe Locash, 4 months ago

Owner: changed from Joe Locash to SecurityAdvisory
Status: assigned → new
v1.0.19 

This release contains a number of security fixes, correctness fixes for edge cases,
and build/packaging improvements.

The public API is binary-compatible with v1.0.18.
Fixed CVEs
    - CVE-2026-45382 (GHSA-hwhx-x2mq-ccr9).
    - CVE-2026-45383 (GHSA-wg9q-ppqw-6q38)

Sample applications
    - dec265: fix SDL out-of-bounds on 4:4:4 streams and on mid-stream resolution changes (closes #460).
    - sherlock265: add framerate-control spinbox (based on #310 by EdenGottlieb).

Fixed at 0de0515daf. Leaving open for SA.

Last edited 4 months ago by Joe Locash (previous) (diff)

comment:4 by Douglas R. Reno, 4 months ago

Resolution: → fixed
Status: new → closed

SA-13.0-099 issued

Note: See TracTickets for help on using tickets.