CVE-2026-33164 identifies a high-severity vulnerability in libde265, an open-source H.265 video codec, affecting versions prior to 1.0.17. This flaw is a segmentation fault triggered by a malformed H.265 PPS NAL unit within the pic_parameter_set::set_derived_values() function. Rated with a CVSS score of 7.5 (High), it poses a denial-of-service risk that can be exploited over the network without requiring user interaction or elevated privileges. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability. Organizations using affected versions should upgrade to libde265 version 1.0.17 or later to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.0.17CPE matchmatch criteria | cpe:2.3:a:struktur:libde265:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.