yocto ▾
›
kirkstone ▾
›
vulnerability
›
CVE-2025-61147
Component Overview
Vulnerability Overview
Name
CVE-2025-61147
Source
NVD (
link
)
Debian (
link
)
Description
strukturag libde265 commit d9fea9d wa discovered to contain a segmentation fault via the component decoder_context::compute_framedrop_table().
CWEs
CWE-120
Published Date
Feb 23, 2026
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://gist.github.com/optionGo/e6567a1c2bc4e0c9fee4e1e8be8d6af9
Third Party Advisory
https://github.com/strukturag/libde265/commit/8b17e0930f77db07f55e0b89399a8f054ddbecf7
Patch
https://github.com/strukturag/libde265/issues/484
Exploit
Analysis
#
Affected Component
Analysis
libde265
Patched
Vulnerability Ratings
#
6.2
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
libde265
buildroot
2025.02.x
1.1.1
Not Affected
libde265
buildroot
master
1.1.1
Not Affected
libde265
yocto
master
1.0.18
Not Affected
libde265
yocto
scarthgap
1.0.16
Patched
Resolved with patches
#
libde265 (yocto:kirkstone)
#
Title
Author
Resolve
1
check for valid integer command line parameters (#484)
Dirk Farin <dirk.farin@gmail.com>
CVE-2025-61147
libde265 (yocto:scarthgap)
#
Title
Author
Resolve
1
check for valid integer command line parameters (#484)
Dirk Farin <dirk.farin@gmail.com>
CVE-2025-61147