that has no active image unit, resulting in attacker-controlled unbounded heap growth. The retained headers are never freed until the picture is released, which may not happen during continuous streaming. Version 1.0.20 patches the issue.
Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-6413-1 | libde265 security update |
Ubuntu USN |
USN-8573-1 | libde265 vulnerabilities |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 24 Jun 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Struktur
Struktur libde265 |
|
| Vendors & Products |
Struktur
Struktur libde265 |
Mon, 22 Jun 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 19 Jun 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.20, a crafted sequence of H.265 NAL units causes `decoder_context::read_slice_NAL()` (`libde265/decctx.cc:481`) to attach slice headers to a finished picture object that has no active image unit, resulting in attacker-controlled unbounded heap growth. The retained headers are never freed until the picture is released, which may not happen during continuous streaming. Version 1.0.20 patches the issue. | |
| Title | libde265 has an unbounded memory leak via orphaned slice headers in `read_slice_NAL` | |
| Weaknesses | CWE-770 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-22T14:00:14.667Z
Reserved: 2026-05-29T14:35:45.902Z
Link: CVE-2026-49337
Updated: 2026-06-22T14:00:05.818Z
Status : Deferred
Published: 2026-06-19T21:17:01.720
Modified: 2026-06-23T15:44:39.343
Link: CVE-2026-49337
No data.
OpenCVE Enrichment
Updated: 2026-06-24T20:30:04Z
Debian DSA
Ubuntu USN