Opened 4 months ago
Closed 4 months ago
#23381 closed enhancement (fixed)
libde265-1.1.0
| Reported by: | Bruce Dubbs | Owned by: | SecurityAdvisory |
|---|---|---|---|
| Priority: | high | Milestone: | 13.1 |
| Component: | BOOK | Version: | git |
| Severity: | medium | Keywords: | |
| Cc: |
Description
New minor version.
Change History (4)
comment:1 by , 4 months ago
| Priority: | normal → high |
|---|
comment:2 by , 4 months ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
comment:3 by , 4 months ago
| Owner: | changed from to |
|---|---|
| Status: | assigned → new |
Fixed at 05d2e55e18. Leaving open for SA.
Note:
See TracTickets
for help on using tickets.

v1.1.0 - security limits Added de265_security_limits parameters to limit the maximum image size and memory that libde265 will use during decoding. Security fixes CVE TBD (GHSA-g2rg-wj66-w594) - Out-of-bounds write in process_reference_picture_set via predicted short-term RPS CVE TBD (GHSA-vv8h-932h-7r86) - Heap buffer overflow in de265_image_get_buffer via SPS dimension integer overflow CVE TBD (GHSA-g5hj-rf9f-7vxm) - Unbounded memory accumulation via orphaned slice headers in read_slice_NAL (GHSA-x27c-jp65-g395) - Quadratic CPU consumption in NAL parser (remove_stuffing_bytes, resize)The only thing I can say professionally about GHSA-vv8h-932h-7r86 is: OUCH. "Massive heap buffer overflow (4 GB write into 1 KB allocation) — crash, high potential for code execution"