CVE-2024-38949, CVE-2024-38950: fix SDL OOB in dec265 display path
authorDebian Multimedia Maintainers <debian-multimedia@lists.debian.org>
Sun, 30 Aug 2026 20:56:35 +0000 (22:56 +0200)
committerMoritz Mühlenhoff <jmm@debian.org>
Sun, 30 Aug 2026 20:56:35 +0000 (22:56 +0200)
commite788d39a7a9a724e86a2ec84dadea9fbb5a42360
treecb2f9bac65a10f45fdc8cd4124201168230059fe
parenta50ac698cb8e5b727de3a95dd95c122adb13d5a5
CVE-2024-38949, CVE-2024-38950: fix SDL OOB in dec265 display path

Origin: upstream, https://github.com/strukturag/libde265/commit/4089de0845e0009e019be4ca5cbebaf2aee0a8ce
Bug: https://github.com/strukturag/libde265/issues/460
Bug-Debian: https://bugs.debian.org/1074416
Applied-Upstream: 1.0.19

Heap buffer overflow in the dec265 SDL output on 4:4:4 streams
(display444as420) and on mid-stream resolution changes.

Gbp-Pq: Name CVE-2024-38949_CVE-2024-38950.patch
dec265/dec265.cc
dec265/sdl.cc
dec265/sdl.hh