CVE-2021-36409: High severity libde265 vulnerability
Last updated 24 July 2024
Other sources
There is an Assertion scalinglistpredmatrixiddelta==1' failed at sps.cc:925 in libde265 v1.0.8 when decoding file, which allows attackers to cause a Denial of Service (DoS) by running the application with a crafted file or possibly have unspecified other impact.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-36409?
CVE-2021-36409 is a vulnerability in libde265 v1.0.8 that allows attackers to cause a Denial of Service (DoS) by running the application with a crafted file or possibly have unspecified other impact.
What is the severity of CVE-2021-36409?
CVE-2021-36409 has a severity rating of 7.8 (high).
What software is affected by CVE-2021-36409?
The affected software includes Struktur Libde265 1.0.8, Debian Debian Linux 10.0, Debian Debian Linux 11.0, and debian/libde265 versions up to and including 1.0.3-1.
How can I fix CVE-2021-36409?
To fix CVE-2021-36409, you should update the libde265 package to version 1.0.11-0+deb10u4 or later.
Where can I find more information about CVE-2021-36409?
You can find more information about CVE-2021-36409 in the following references: [GitHub](https://github.com/strukturag/libde265/issues/300), [Debian LTS Announce](https://lists.debian.org/debian-lts-announce/2022/12/msg00027.html), and [Debian Security Advisory](https://www.debian.org/security/2023/dsa-5346).