PT-2022-7262 · Libde265+3 · Libde265+3

Peng Deng

·

Published

2022-10-10

·

Updated

2025-01-28

·

CVE-2022-43238

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Libde265 version 1.0.8
Description The issue is related to the ff hevc put hevc qpel h 3 v 3 sse() function in the Libde265 video codec implementation, which can cause a buffer overflow in memory. This can be exploited by a remote attacker using a specially crafted video file to cause a Denial of Service (DoS). The vulnerability allows attackers to cause a crash via the ff hevc put hevc qpel h 3 v 3 sse() function in sse-motion.cc.
Recommendations For Libde265 version 1.0.8, update to version 1.0.11 to fix the security issue. As a temporary workaround, consider disabling the ff hevc put hevc qpel h 3 v 3 sse() function until a patch is available. Restrict access to the sse-motion.cc module to minimize the risk of exploitation. Avoid using crafted video files that can trigger the Denial of Service (DoS) until the issue is resolved.

Exploit

Fix

DoS

Out of bounds Read

Resource Exhaustion

Weakness Enumeration

Related Identifiers

BDU:2024-01211
CVE-2022-43238
DLA-3280-1
DSA-5346-1
MGASA-2023-0093
ROSA-SA-2025-2630
ROSA-SA-2025-2631
USN-6627-1

Affected Products

Astra Linux
Libde265
Linuxmint
Ubuntu