CVE-2026-49346Disclosure(struktur / libde265)

LOWCVSS 7.1 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

libde265 is an open source implementation of the h.265 video codec. Prior to version 1.1.0, a crafted H.265 bitstream with large SPS dimensions and 16-bit bit depth causes a signed integer overflow in `de265_image_get_buffer()` (`libde265/image.cc:128`). The overflow wraps the plane allocation size to a small value (~1 KB), but the subsequent `fill_image()` call computes the real size using `size_t`, writing ~4 GB into the undersized heap buffer. Version 1.1.0 patches the issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-190

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • libde265

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
libde265

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-06-19: 2Technical Details · 2026-06-19: 206-19
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-49346 libde265 is an open source implementation of the h.265 video codec. Prior to version 1.1.0, a crafted H.265 bitstream with large SPS dimensions and 16-bit bit depth c… https://www.cve.org/CVERecord?id=CVE-2026-49346 ----- Traducción: CVE-2026-49346 lib… http://infoflow.cloud`

    Post summary

    The tweet announces CVE‑2026‑49346, noting that libde265 versions prior to 1.1.0 are vulnerable to crafted H.265 bitstreams featuring large SPS dimensions and 16‑bit bit depth.

    0000024
    82 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-49346 libde265 is an open source implementation of the h.265 video codec. Prior to version 1.1.0, a crafted H.265 bitstream with large SPS dimensions and 16-bit bit depth c… https://www.cve.org/CVERecord?id=CVE-2026-49346

    Post summary

    The post references CVE-2026-49346, mentioning a crafted bitstream vulnerability in libde265 prior to version 1.1.0, but it provides no PoC, exploit code, patches, or evidence of active exploitation.

    00000252
    57.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appstrukturlibde265---

Explore more