yocto ▾
›
kirkstone ▾
›
vulnerability
›
CVE-2022-1253
Component Overview
Vulnerability Overview
Name
CVE-2022-1253
Source
NVD (
link
)
Debian (
link
)
Description
Heap-based Buffer Overflow in GitHub repository strukturag/libde265 prior to and including 1.0.8. The fix is established in commit 8e89fe0e175d2870c39486fdd09250b230ec10b8 but does not yet belong to an official release.
CWEs
CWE-122
CWE-787
Published Date
Apr 6, 2022
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://github.com/strukturag/libde265/commit/8e89fe0e175d2870c39486fdd09250b230ec10b8
Patch
https://huntr.dev/bounties/1-other-strukturag/libde265
Exploit
https://github.com/strukturag/libde265/commit/8e89fe0e175d2870c39486fdd09250b230ec10b8
Patch
https://huntr.dev/bounties/1-other-strukturag/libde265
Exploit
Analysis
#
Affected Component
Analysis
libde265
Patched
Vulnerability Ratings
#
9.8
CVSSv31
7.4
other
7.5
CVSSv2
Others affected components
#
Name
Project
Project Version
Version
Status
libde265
buildroot
2025.02.x
1.1.1
Not Affected
libde265
buildroot
master
1.1.1
Not Affected
libde265
yocto
master
1.0.18
Not Affected
libde265
yocto
scarthgap
1.0.16
Not Affected
Resolved with patches
#
libde265 (yocto:kirkstone)
#
Title
Author
Resolve
1
error on out-of-range cpb_cnt_minus1 (oss-fuzz issue 27590)
Dirk Farin <dirk.farin@gmail.com>
CVE-2022-1253