CVE-2026-49337

EUVD-2026-38078
libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.20, a crafted sequence of H.265 NAL units causes `decoder_context::read_slice_NAL()` (`libde265/decctx.cc:481`) to attach slice headers to a finished picture object
that has no active image unit, resulting in attacker-controlled unbounded heap growth. The retained headers are never freed until the picture is released, which may not happen during continuous streaming. Version 1.0.20 patches the issue.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 9%
Debian logo
Debian Releases
Debian Product
Codename
libde265
bookworm
vulnerable
bullseye
vulnerable
bullseye (security)
vulnerable
forky
1.1.1-1
fixed
sid
1.1.1-1
fixed
trixie
vulnerable
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libde265
bionic
Fixed 1.0.2-2ubuntu0.18.04.1~esm6
released
focal
Fixed 1.0.4-1ubuntu0.4+esm2
released
jammy
Fixed 1.0.8-1ubuntu0.3+esm2
released
noble
Fixed 1.0.15-1ubuntu0.1
released
questing
ignored
resolute
Fixed 1.0.16-1ubuntu0.1~esm1
released
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
libde265
Amazon Linux 2023
0:1.0.18-1.amzn2023.0.2
fixed
libde265-debuginfo
Amazon Linux 2023
0:1.0.18-1.amzn2023.0.2
fixed
libde265-debugsource
Amazon Linux 2023
0:1.0.18-1.amzn2023.0.2
fixed
libde265-devel
Amazon Linux 2023
0:1.0.18-1.amzn2023.0.2
fixed