CVE-2026-33164
published 2026-03-20CVE-2026-33164: libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.17, a malformed H.265 PPS NAL unit causes a segmentation fault in…
PriorityP339high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.35%
27.2th percentile
libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.17, a malformed H.265 PPS NAL unit causes a segmentation fault in pic_parameter_set::set_derived_values(). This issue has been patched in version 1.0.17.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libde265 | < libde265 1.0.18-1 (forky) | libde265 1.0.18-1 (forky) |
| struktur | libde265 | < 1.0.17 | 1.0.17 |
| struktur | libde265 | >= 0 < 1.0.18-1 | 1.0.18-1 |
| strukturag | libde265 | < 1.0.17 | 1.0.17 |
| ubuntu | libde265 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv4.08.7HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
osv8.7HIGH
vendor_debian8.7HIGH
vendor_ubuntu3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
libde265 vulnerabilities
vendor_ubuntu·2026-07-20·CVSS 3.3
CVE-2026-45382 [LOW] libde265 vulnerabilities
Title: libde265 vulnerabilities
Summary: Several security issues were fixed in libde265.
It was discovered that libde265 did not properly manage memory under
certain circumstances. An attacker could possibly use this issue to
cause libde265 to crash, resulting in a denial of service. This issue
only affected Ubuntu 22.04 LTS. (CVE-2023-51792)
It was discovered that libde265 did not properly handle certain
malformed media files, leading to a heap buffer overflow. An attacker
could possibly use this issue to cause libde265 to crash, resulting in
a denial of service. (CVE-2024-38949, CVE-2024-38950)
It was discovered that libde265 did not properly handle certain
malformed input, leading to a segmentation fault. An attacker could
possibly use this issue to cause libde265 to crash, resultin
Debian
CVE-2026-33164: libde265 - libde265 is an open source implementation of the h.265 video codec. Prior to ver...
vendor_debian·2026·CVSS 8.7
CVE-2026-33164 [HIGH] CVE-2026-33164: libde265 - libde265 is an open source implementation of the h.265 video codec. Prior to ver...
libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.17, a malformed H.265 PPS NAL unit causes a segmentation fault in pic_parameter_set::set_derived_values(). This issue has been patched in version 1.0.17.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 1.0.18-1)
sid: resolved (fixed in 1.0.18-1)
trixie: open
OSV
CVE-2026-33164: libde265 is an open source implementation of the h
osv·2026-03-20·CVSS 8.7
CVE-2026-33164 [HIGH] CVE-2026-33164: libde265 is an open source implementation of the h
libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.17, a malformed H.265 PPS NAL unit causes a segmentation fault in pic_parameter_set::set_derived_values(). This issue has been patched in version 1.0.17.
No detection rules found.
No public exploits indexed.
2026-03-20
Published