CVE-2026-49337
published 2026-06-19CVE-2026-49337: libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.20, a crafted sequence of H.265 NAL units causes…
PriorityP420medium4.3CVSS 3.1
AVNACLPRNUIRSUCNINAL
EPSS
0.19%
9.4th percentile
libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.20, a crafted sequence of H.265 NAL units causes `decoder_context::read_slice_NAL()` (`libde265/decctx.cc:481`) to attach slice headers to a finished picture object
that has no active image unit, resulting in attacker-controlled unbounded heap growth. The retained headers are never freed until the picture is released, which may not happen during continuous streaming. Version 1.0.20 patches the issue.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| strukturag | libde265 | < 1.0.20 | 1.0.20 |
| ubuntu | libde265 | — | — |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
vendor_ubuntu3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
libde265 vulnerabilities
vendor_ubuntu·2026-07-20·CVSS 3.3
CVE-2026-45382 [LOW] libde265 vulnerabilities
Title: libde265 vulnerabilities
Summary: Several security issues were fixed in libde265.
It was discovered that libde265 did not properly manage memory under
certain circumstances. An attacker could possibly use this issue to
cause libde265 to crash, resulting in a denial of service. This issue
only affected Ubuntu 22.04 LTS. (CVE-2023-51792)
It was discovered that libde265 did not properly handle certain
malformed media files, leading to a heap buffer overflow. An attacker
could possibly use this issue to cause libde265 to crash, resulting in
a denial of service. (CVE-2024-38949, CVE-2024-38950)
It was discovered that libde265 did not properly handle certain
malformed input, leading to a segmentation fault. An attacker could
possibly use this issue to cause libde265 to crash, resultin
VulDB
strukturag libde265 up to 1.0.19 Sequence libde265/decctx.cc read_slice_NAL allocation of resources (GHSA-g5hj-rf9f-7vxm / EUVD-2026-38078)
vuldb·2026-06-19
CVE-2026-49337 [LOW] strukturag libde265 up to 1.0.19 Sequence libde265/decctx.cc read_slice_NAL allocation of resources (GHSA-g5hj-rf9f-7vxm / EUVD-2026-38078)
A vulnerability labeled as problematic has been found in strukturag libde265 up to 1.0.19. Affected by this issue is the function decoder_context::read_slice_NAL of the file libde265/decctx.cc of the component Sequence Handler. Such manipulation leads to allocation of resources.
This vulnerability is traded as CVE-2026-49337. The attack may be launched remotely. There is no exploit available.
The affected component should be upgraded.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-19
Published