Out-of-bounds write in libde265 - CVE-2026-49295
Published: September 4, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an out-of-bounds write in process_reference_picture_set when processing a predicted short-term reference picture set. A remote attacker can provide a specially crafted predicted short-term reference picture set to cause a denial of service.
User interaction is required.