Use-after-free in libde265 - #VU146895
Published: September 4, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose information or execute arbitrary code.
The vulnerability exists due to use-after-free in decoder_context::reset() when processing a dependent H.265 slice after a decoder reset. A remote attacker can trick the victim into processing a crafted H.265 stream to disclose information or execute arbitrary code.
User interaction is required.