Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-49337

Опубликовано: 19 июн. 2026
Источник: ubuntu
Приоритет: medium
CVSS3: 4.3

Описание

libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.20, a crafted sequence of H.265 NAL units causes decoder_context::read_slice_NAL() (libde265/decctx.cc:481) to attach slice headers to a finished picture object that has no active image unit, resulting in attacker-controlled unbounded heap growth. The retained headers are never freed until the picture is released, which may not happen during continuous streaming. Version 1.0.20 patches the issue.

РелизСтатусПримечание
devel

needs-triage

esm-apps-legacy/xenial

released

1.0.2-2ubuntu0.16.04.1~esm6
esm-apps/bionic

released

1.0.2-2ubuntu0.18.04.1~esm6
esm-apps/focal

released

1.0.4-1ubuntu0.4+esm2
esm-apps/jammy

released

1.0.8-1ubuntu0.3+esm2
esm-apps/resolute

released

1.0.16-1ubuntu0.1~esm1
jammy

needed

noble

released

1.0.15-1ubuntu0.1
questing

ignored

end of life, was needs-triage
resolute

needed

Показывать по

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
nvd
около 1 месяца назад

libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.20, a crafted sequence of H.265 NAL units causes `decoder_context::read_slice_NAL()` (`libde265/decctx.cc:481`) to attach slice headers to a finished picture object that has no active image unit, resulting in attacker-controlled unbounded heap growth. The retained headers are never freed until the picture is released, which may not happen during continuous streaming. Version 1.0.20 patches the issue.

CVSS3: 4.3
debian
около 1 месяца назад

libde265 is an open source implementation of the h.265 video codec. Pr ...

CVSS3: 4.3
redos
19 дней назад

Уязвимость libde265

4.3 Medium

CVSS3