CVE-2026-33165: heap out-of-bounds write in libde265 1.0.16

Published Mar 20, 2026
·
Updated

libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.17, a crafted HEVC bitstream causes an out-of-bounds heap write confirmed by AddressSanitizer. The trigger is a stale ctbinfo.log2unitSize after an SPS change where PicWidthInCtbsY and PicHeightInCtbsY stay constant but Log2CtbSizeY changes, causing setSliceHeaderIndex to index past the allocated image metadata array and write 2 bytes past the end of a heap allocation. This issue has been patched in version 1.0.17.

Affected Software

2 affected components
Libde265 Libde265<1.0.17
struktur libde265<1.0.17

Event History

Mar 20, 2026
CVE Published
via MITRE·08:32 PM
Data Sourced
via MITRE·08:32 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:17 PM
RemedyDescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-33165?

CVE-2026-33165 has a severity level classified as high due to the potential for remote code execution through a crafted HEVC bitstream.

2

How do I fix CVE-2026-33165?

To mitigate CVE-2026-33165, upgrade libde265 to version 1.0.17 or later immediately.

3

What does CVE-2026-33165 affect?

CVE-2026-33165 affects libde265 versions prior to 1.0.17, which is an implementation of the h.265 video codec.

4

What type of vulnerability is CVE-2026-33165?

CVE-2026-33165 is classified as a heap out-of-bounds write vulnerability.

5

How can CVE-2026-33165 be triggered?

CVE-2026-33165 can be triggered by a crafted HEVC bitstream that leads to an out-of-bounds write due to stale ctb_info.log2unitSize.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203