CVE-2026-49295: bound aggregate short-term RPS size
authorDebian Multimedia Maintainers <debian-multimedia@lists.debian.org>
Thu, 6 Aug 2026 05:05:03 +0000 (13:05 +0800)
committerAron Xu <aron@debian.org>
Thu, 6 Aug 2026 05:05:03 +0000 (13:05 +0800)
commite828c1f0566b3084610280fa780e0e0d0bf6e861
tree0ec27aabaf0b856dfd9f779c57e1b477eac92ded
parent5a6e0aef1c2b42c86af15c4bf2213465f366d029
CVE-2026-49295: bound aggregate short-term RPS size

Origin: upstream, https://github.com/strukturag/libde265/commit/691f3a3c55b3d32478c4a49895dee061a282652b
Bug: https://github.com/strukturag/libde265/security/advisories/GHSA-g2rg-wj66-w594
Bug-Debian: https://bugs.debian.org/1140431
Applied-Upstream: 1.1.0

Missing aggregate bound check on predicted reference picture set entries
allows exceeding the 16-entry array, an out-of-bounds array write in
process_reference_picture_set().

Gbp-Pq: Name CVE-2026-49295.patch
libde265/refpic.cc