PT-2026-26677 · Libde265 · Libde265

Riverside1114

·

Published

2026-03-20

·

Updated

2026-04-10

·

CVE-2026-33164

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions libde265 versions prior to 1.0.17
Description libde265 is an open source implementation of the h.265 video codec. A malformed H.265 PPS NAL unit can cause a segmentation fault in the pic parameter set::set derived values() function.
Recommendations Update to version 1.0.17 or later.

Exploit

Fix

Heap Based Buffer Overflow

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

CVE-2026-33164
ECHO-3083-2A98-5F9B
GHSA-WQRF-6RF5-V78R

Affected Products

Libde265