CVE-2026-33165 Details
Description
libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.17, a crafted HEVC bitstream causes an out-of-bounds heap write confirmed by AddressSanitizer. The trigger is a stale ctb_info.log2unitSize after an SPS change where PicWidthInCtbsY and PicHeightInCtbsY stay constant but Log2CtbSizeY changes, causing set_SliceHeaderIndex to index past the allocated image metadata array and write 2 bytes past the end of a heap allocation. This issue has been patched in version 1.0.17.
A heap out-of-bounds write vulnerability has been identified in libde265 versions prior to 1.0.17. This issue arises when a crafted HEVC bitstream is processed, leading to a write operation that exceeds the allocated memory bounds. The vulnerability is triggered by a stale 'ctb_info.log2unitSize' following a change in the Sequence Parameter Set (SPS), where certain width and height parameters remain constant while the logarithmic block size changes. This discrepancy causes the 'set_SliceHeaderIndex' function to access memory beyond the allocated image metadata array, writing two bytes past the end of a heap allocation. The vulnerability has been patched in version 1.0.17.
Users can upgrade to libde265 version 1.0.17 or later to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 24, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-787 | Out-of-bounds Write | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| struktur libde265 | < 1.0.17 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 23, 2026 | Initial Analysis | [email protected] |
| Mar 20, 2026 | New CVE Received | [email protected] |