CVE-2026-33164

libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.17, a malformed H.265 PPS NAL unit causes a segmentation fault in pic_parameter_set::set_derived_values(). This issue has been patched in version 1.0.17.
Configurations

Configuration 1 (hide)

cpe:2.3:a:struktur:libde265:*:*:*:*:*:*:*:*

History

23 Mar 2026, 20:05

Type Values Removed Values Added
CWE CWE-476
References () https://github.com/strukturag/libde265/releases/tag/v1.0.17 - () https://github.com/strukturag/libde265/releases/tag/v1.0.17 - Release Notes
References () https://github.com/strukturag/libde265/security/advisories/GHSA-wqrf-6rf5-v78r - () https://github.com/strukturag/libde265/security/advisories/GHSA-wqrf-6rf5-v78r - Exploit, Vendor Advisory
CPE cpe:2.3:a:struktur:libde265:*:*:*:*:*:*:*:*
First Time Struktur libde265
Struktur
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

20 Mar 2026, 21:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-20 21:17

Updated : 2026-03-23 20:05


NVD link : CVE-2026-33164

Mitre link : CVE-2026-33164

CVE.ORG link : CVE-2026-33164


JSON object : View

Products Affected

struktur

  • libde265
CWE
CWE-122

Heap-based Buffer Overflow

CWE-476

NULL Pointer Dereference