{"id":"CVE-2026-54240","summary":"libde265: Pixel accessor signed integer overflow causes heap OOB read/write","details":"libde265 is an open source implementation of the h.265 video codec. Versions prior to 1.1.1 use signed 32-bit arithmetic to calculate pixel offsets, allowing a crafted HEVC stream with large image dimensions to trigger an integer overflow and cause out-of-bounds heap reads or writes, potentially disclosing data, corrupting memory, or crashing the decoder. Version 1.1.1 contains a patch.","aliases":["GHSA-ccfw-29x7-rrx3"],"modified":"2026-09-13T08:12:26.337041Z","published":"2026-09-11T21:20:59.855Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-190","CWE-787"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54240.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54240.json"},{"type":"ADVISORY","url":"https://github.com/strukturag/libde265/security/advisories/GHSA-ccfw-29x7-rrx3"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54240"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/strukturag/libde265","events":[{"introduced":"0"},{"fixed":"4dd701fffac01632ffd5cabc5ef10deb56accba1"}],"database_specific":{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"0"},{"fixed":"1.1.1"}]}}],"versions":["v1.1.0","v1.0.19","v1.0.18","v1.0.17","v1.0.16","v1.0.15","v1.0.14","v1.0.13","v1.0.12","v1.0.11","v1.0.10","v1.0.9","v1.0.8","v1.0.7","v1.0.6","v1.0.5","v1.0.4","v1.0.3","v1.0.0","v0.5","v0.4","v0.3","v0.2","v0.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-54240.json","vanir_signatures_modified":"2026-09-13T08:12:26Z","vanir_signatures":[{"target":{"file":"libde265/x86/sse-dct.cc"},"deprecated":false,"digest":{"line_hashes":["272535367608003614774956504665802114340","272077234282362750628067979549333075005","190708680389475610646129489202418337357","322809031387022381988928415739415820058","108587633537507210242609878158511307392","305407463024304548130196606906410878762","83794420774628235930683358852912822456","111031661395276687799481435681795647398"],"threshold":0.9},"id":"CVE-2026-54240-734a4617","signature_type":"Line","signature_version":"v1","source":"https://github.com/strukturag/libde265/commit/4dd701fffac01632ffd5cabc5ef10deb56accba1"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H"}]}