CVE-2026-49295Disclosure(struktur / libde265)

LOWCVSS 7.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.20, a crafted H.265 bitstream can cause an out-of-bounds array write in `decoder_context::process_reference_picture_set()` (`libde265/decctx.cc:1376`). The root cause is a missing aggregate bound check on predicted short-term reference picture set entries. Individual list sizes are validated, but the combined count after predicted RPS construction can exceed the 16-entry `PocStFoll` array, writing at index 16. Version 1.0.20 patches the issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • libde265

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-06-19); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
libde265

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-06-19: 2Mentions · 2026-06-20: 1Technical Details · 2026-06-19: 206-1906-20
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-06-192
Disclosure2
2026-06-201
General1
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-49295 Out-of-Bounds Array Write in libde265 Prior to Version 1.0.20 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-49295

    Post summary

    The text merely lists CVE‑2026‑49295 with a brief note and a link, providing no additional context, PoC, or exploitation details.

    0000041
    4.1K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-49295 libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.20, a crafted H.265 bitstream can cause an out-of-bounds array write in `deco… https://www.cve.org/CVERecord?id=CVE-2026-49295 ----- Traducción: CVE-2026-49295 lib… http://infoflow.cloud`

    Post summary

    CVE-2026-49295 in libde265 allows crafted H.265 bitstreams to trigger an out‑of‑bounds array write; no PoC, exploit code, or active exploitation is reported.

    0000030
    82 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-49295 libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.20, a crafted H.265 bitstream can cause an out-of-bounds array write in `deco… https://www.cve.org/CVERecord?id=CVE-2026-49295

    Post summary

    The tweet announces a memory corruption vulnerability (out-of-bounds array write) in libde265 prior to version 1.0.20, with no evidence of exploitation or patch information.

    00000213
    57.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appstrukturlibde265---

Explore more