Heap-based buffer overflow in libde265 - CVE-2026-49346
Published: September 4, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service or modify data.
The vulnerability exists due to a heap-based buffer overflow caused by an integer overflow in de265_image_get_buffer when processing SPS dimensions. A remote attacker can supply a crafted HEVC bitstream to cause a denial of service or modify data.
User interaction is required.