CVE-2026-33164: NULL Pointer Dereference in libde265
Last updated 10 July 2026
Other sources
libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.17, a malformed H.265 PPS NAL unit causes a segmentation fault in picparameterset::setderivedvalues(). This issue has been patched in version 1.0.17.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/libde265to a version that resolves this vulnerability.Fixed in 1.0.11-0+deb11u4Fixed in 1.1.1-1 - Upgrade
Upgrade
libde265to a version that resolves this vulnerability.Fixed in 1.0.17
Event History
Frequently Asked Questions
What is the severity of CVE-2026-33164?
CVE-2026-33164 is classified as a high severity vulnerability due to the potential for denial of service through a null pointer dereference.
How do I fix CVE-2026-33164?
To fix CVE-2026-33164, upgrade libde265 to version 1.0.17 or later.
What causes CVE-2026-33164?
CVE-2026-33164 is caused by a malformed H.265 PPS NAL unit that leads to a segmentation fault in libde265.
Which versions of libde265 are affected by CVE-2026-33164?
Versions of libde265 prior to 1.0.17 are affected by CVE-2026-33164.
Is CVE-2026-33164 an open source vulnerability?
Yes, CVE-2026-33164 affects the open source implementation of the H.265 video codec in libde265.