Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-49337

Опубликовано: 19 июн. 2026
Источник: debian
EPSS Низкий

Описание

libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.20, a crafted sequence of H.265 NAL units causes `decoder_context::read_slice_NAL()` (`libde265/decctx.cc:481`) to attach slice headers to a finished picture object that has no active image unit, resulting in attacker-controlled unbounded heap growth. The retained headers are never freed until the picture is released, which may not happen during continuous streaming. Version 1.0.20 patches the issue.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libde265fixed1.1.1-1package

Примечания

  • https://github.com/strukturag/libde265/security/advisories/GHSA-g5hj-rf9f-7vxm

  • Fixed by: https://github.com/strukturag/libde265/commit/683cb9fa603e35840642f98765ab95cdb71cadf9 (v1.1.0)

EPSS

Процентиль: 9%
0.00194
Низкий

Связанные уязвимости

CVSS3: 4.3
ubuntu
около 1 месяца назад

libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.20, a crafted sequence of H.265 NAL units causes `decoder_context::read_slice_NAL()` (`libde265/decctx.cc:481`) to attach slice headers to a finished picture object that has no active image unit, resulting in attacker-controlled unbounded heap growth. The retained headers are never freed until the picture is released, which may not happen during continuous streaming. Version 1.0.20 patches the issue.

CVSS3: 4.3
nvd
около 1 месяца назад

libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.20, a crafted sequence of H.265 NAL units causes `decoder_context::read_slice_NAL()` (`libde265/decctx.cc:481`) to attach slice headers to a finished picture object that has no active image unit, resulting in attacker-controlled unbounded heap growth. The retained headers are never freed until the picture is released, which may not happen during continuous streaming. Version 1.0.20 patches the issue.

CVSS3: 4.3
redos
19 дней назад

Уязвимость libde265

EPSS

Процентиль: 9%
0.00194
Низкий