CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-49295

unknowncovered by 1 sourcefirst seen 2026-07-20
It was discovered that libde265 did not properly manage memory under certain circumstances. An attacker could possibly use this issue to cause libde265 to crash, resulting in a denial of service. This issue only affected Ubuntu 22.04 LTS. (CVE-2023-51792) It was discovered that libde265 did not properly handle certain malformed media files, leading to a heap buffer overflow. An attacker could possibly use this issue to cause libde265 to crash, resulting in a denial of service. (CVE-2024-38949, CVE-2024-38950) It was discovered that libde265 did not properly handle certain malformed input, leading to a segmentation fault. An attacker could possibly use this issue to cause libde265 to crash, resulting in a denial of service. (CVE-2025-61147) It was discovered that libde265 did not properly handle a malformed H.265 PPS NAL unit, leading to a segmentation fault. An attacker could possibly use this issue to cause libde265 to crash, resulting in a denial of service. (CVE-2026-33164) It was discovered that libde265 did not properly handle certain crafted HEVC bitstreams, leading to an out-of-bounds write. An attacker could possibly use this issue to cause libde265 to crash, resulting in a denial of service. (CVE-2026-33165) Valentin Mercier discovered that libde265 did not properly validate tile geometry when handling crafted media files, leading to an out-of-bounds read. An attacker could possibly use this issue to cause libde265 to crash, resulting in a denial of service, or to obtain sensitive information. (CVE-2026-45382) It was discovered that libde265 did not properly validate certain values when decoding crafted media files, leading to an out-of-bounds read. An attacker could possibly use this issue to cause libde265 to crash, resulting in a denial of service, or to obtain sensitive information. (CVE-2026-45383) Ying Dong discovered that libde265 did not properly validate reference picture set entries when handling a crafted H.265 bitstream, leading to an out-of-bou

CSIRTS triage

What
Multiple vulnerabilities in libde265 could allow an attacker to cause the library to crash.
Who is affected
Users of libde265 on Ubuntu 22.04 LTS.
Urgency
Remediation is necessary as the vulnerabilities can lead to denial of service.
Action
Apply the latest patches for libde265 to address the vulnerabilities.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-49295

Get an email if CVE-2026-49295 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-49295

CVE.org record

Embed the live status

CVE-2026-49295 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-49295 status](https://www.csirts.com/badge/CVE-2026-49295)](https://www.csirts.com/cve/CVE-2026-49295)