Security readout for executives and security teams
Plain-English summary
CVE-2022-43245 is a crash bug in libde265, a video decoding library. A crafted video file can cause vulnerable software using libde265 v1.0.8 to crash, creating denial of service rather than confirmed data theft or code execution.
Executive priority
Treat as a moderate operational reliability risk. Prioritize internet-facing or customer-upload media pipelines first because a crafted file could interrupt service without requiring authentication.
Technical view
The issue is a segmentation violation in sao.cc, specifically apply_sao_internal<unsigned short>. The CVE maps it to CWE-787 and rates availability impact high. The attack requires user interaction with a crafted video file and no privileges.
Likely exposure
Exposure is most likely where libde265 processes untrusted HEVC/H.265 media, including server-side upload processing, media conversion, thumbnailing, or user desktop preview workflows using vulnerable packages.
Exploitation context
The source bundle does not show CISA KEV listing or active exploitation evidence. Public references include a GitHub issue and Debian security advisories, supporting remediation urgency for systems handling untrusted video.
Researcher notes
Evidence supports denial of service from crafted media, not confirmed remote code execution. The bundle does not identify exact non-Debian fixed versions, exploit maturity, or broader affected product lists beyond libde265 v1.0.8.
Mitigation direction
- Apply vendor or distribution libde265 security updates promptly.
- For Debian, review DLA-3280-1 and DSA-5346 package guidance.
- Reduce processing of untrusted video on vulnerable systems until updated.
- Isolate media parsing services from critical business systems.
- Check upstream libde265 guidance if using source-built versions.
Validation and detection
- Inventory applications and hosts that include or link libde265.
- Confirm whether libde265 v1.0.8 or vulnerable distribution packages are present.
- Verify patched packages match Debian or vendor advisory guidance.
- Review media processing services for untrusted video ingestion paths.
- Check crash telemetry for libde265 decoder faults.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CWE-787: Exact CWE lookup
Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
Open ATT&CK lookupCVE-2022-43245 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Medium
- CVSS
- 6.5 (3.1)
- Known Exploited
- No
- Published
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS vector scores
1 official scoreWe collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H2.83.6Primary CVE scoreVulnerability scoring details
Base CVSS 3.1 score
6.5MediumVector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Source materials
- CVE List V5 sourceCVE List V5
- https://github.com/strukturag/libde265/issues/352CVE reference
- [debian-lts-announce] 20230124 [SECURITY] [DLA 3280-1] libde265 security updateCVE reference · mailing-list
- DSA-5346CVE reference · vendor-advisory
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
Out-of-bounds Write
Out-of-bounds Write represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.
