CVE-2026-33164: Struktur LIBDE265
High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.
libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.17, a malformed H.265 PPS NAL unit causes a segmentation fault in pic_parameter_set::set_derived_values(). This issue has been patched in version 1.0.17.
Affected products
- Struktur LIBDE265: before 1.0.17 (fixed in 1.0.17)
Published 2026-03-20. Last modified 2026-06-17.