CVE-2024-38949, CVE-2024-38950: fix SDL OOB in dec265 display path
authorDebian Multimedia Maintainers <debian-multimedia@lists.debian.org>
Thu, 6 Aug 2026 05:05:03 +0000 (13:05 +0800)
committerAron Xu <aron@debian.org>
Thu, 6 Aug 2026 05:05:03 +0000 (13:05 +0800)
commitfdfe556cc81c82929ddde245ab545412ec27e075
treee83f9c6a8800b739624c77441258599e95292b91
parent3c265295be594f3b992c0e84672e8d5bccc335a1
CVE-2024-38949, CVE-2024-38950: fix SDL OOB in dec265 display path

Origin: upstream, https://github.com/strukturag/libde265/commit/4089de0845e0009e019be4ca5cbebaf2aee0a8ce
Bug: https://github.com/strukturag/libde265/issues/460
Bug-Debian: https://bugs.debian.org/1074416
Applied-Upstream: 1.0.19

Heap buffer overflow in the dec265 SDL output on 4:4:4 streams
(display444as420) and on mid-stream resolution changes.

Gbp-Pq: Name CVE-2024-38949_CVE-2024-38950.patch
dec265/dec265.cc
dec265/sdl.cc
dec265/sdl.hh