CVE-2026-49337
MEDIUMlibde265 has an unbounded memory leak via orphaned slice headers in `read_slice_NAL`
Title source: cnaDescription
libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.20, a crafted sequence of H.265 NAL units causes `decoder_context::read_slice_NAL()` (`libde265/decctx.cc:481`) to attach slice headers to a finished picture object that has no active image unit, resulting in attacker-controlled unbounded heap growth. The retained headers are never freed until the picture is released, which may not happen during continuous streaming. Version 1.0.20 patches the issue.
References (2)
Core 2
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/strukturag/libde265/security/advisories/GHSA-g5hj-rf9f-7vxm
X_Refsource_Misc x_refsource_misc
https://github.com/strukturag/libde265/commit/683cb9fa603e35840642f98765ab95cdb71cadf9
Scores
CVSS v3
4.3
EPSS
0.0019
EPSS Percentile
9.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-770
Status
published
Products (1)
strukturag/libde265
< 1.0.20
Published
Jun 19, 2026
Tracked Since
Jun 20, 2026