PT-2026-51026 · Libde265+3 · Libde265+3

·

CVE-2026-49295

·

Published

2026-06-19

·

Updated

2026-08-25

CVSS v2.0

8.5

High

VectorAV:N/AC:L/Au:N/C:N/I:P/A:C
Name of the Vulnerable Software and Affected Versions libde265 versions prior to 1.0.20
Description An out-of-bounds array write exists in the h.265 video codec implementation. A crafted H.265 bitstream can trigger this issue within the decoder context::process reference picture set() function. The problem stems from a missing aggregate bound check on predicted short-term reference picture set entries; while individual list sizes are validated, the combined count after construction can exceed the 16-entry PocStFoll array, resulting in a write at index 16. This memory corruption could potentially allow an attacker to execute arbitrary code.
Recommendations Update to version 1.0.20.

Exploit

Fix

DoS

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-13679
CVE-2026-49295
ECHO-8E85-F1BA-F7F7
GHSA-G2RG-WJ66-W594
USN-8573-1

Affected Products

Linuxmint
Red Os
Ubuntu
Libde265