{"id":"CVE-2026-33164","summary":"NULL Pointer Dereference in libde265","details":"libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.17, a malformed H.265 PPS NAL unit causes a segmentation fault in pic_parameter_set::set_derived_values(). This issue has been patched in version 1.0.17.","aliases":["GHSA-wqrf-6rf5-v78r"],"modified":"2026-04-12T20:14:10.279869Z","published":"2026-03-20T20:33:04.054Z","database_specific":{"cna_assigner":"GitHub_M","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/33xxx/CVE-2026-33164.json","cwe_ids":["CWE-122"]},"references":[{"type":"WEB","url":"https://github.com/strukturag/libde265/releases/tag/v1.0.17"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/33xxx/CVE-2026-33164.json"},{"type":"ADVISORY","url":"https://github.com/strukturag/libde265/security/advisories/GHSA-wqrf-6rf5-v78r"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-33164"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/strukturag/libde265","events":[{"introduced":"0"},{"fixed":"f3d916c8e63e510bda1f9cf5e8710259c22afece"}]}],"versions":["v0.1","v0.2","v0.3","v0.4","v0.5","v1.0.0","v1.0.10","v1.0.11","v1.0.12","v1.0.13","v1.0.14","v1.0.15","v1.0.16","v1.0.3","v1.0.4","v1.0.5","v1.0.6","v1.0.7","v1.0.8","v1.0.9"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-33164.json","vanir_signatures":[{"id":"CVE-2026-33164-388c898b","signature_version":"v1","target":{"file":"sherlock265/VideoWidget.cc","function":"VideoWidget::paintEvent"},"source":"https://github.com/strukturag/libde265/commit/f3d916c8e63e510bda1f9cf5e8710259c22afece","deprecated":false,"signature_type":"Function","digest":{"function_hash":"224189621832908547208584845959293867245","length":564}},{"id":"CVE-2026-33164-6ee60a4c","signature_version":"v1","target":{"file":"sherlock265/VideoWidget.cc","function":"VideoWidget::VideoWidget"},"source":"https://github.com/strukturag/libde265/commit/f3d916c8e63e510bda1f9cf5e8710259c22afece","deprecated":false,"signature_type":"Function","digest":{"function_hash":"327840637841273794815898644878905505991","length":364}},{"id":"CVE-2026-33164-99af71a4","signature_version":"v1","target":{"file":"sherlock265/VideoWidget.cc"},"source":"https://github.com/strukturag/libde265/commit/f3d916c8e63e510bda1f9cf5e8710259c22afece","deprecated":false,"signature_type":"Line","digest":{"threshold":0.9,"line_hashes":["24195985884818460783815628466886685969","147038544006205557352957683921935214158","332270579816490930149395567689058003278","261987140283495801479336438506181096998","434014289267642594433253264005132899","168652729852070854314972564615697156958","118537600665570856582955531051773423212","331797459368371019932686990456084375128","130059418393864323628047821926512668","52533368177343838076000847856234591642","281675411347226717154703759322655818114","41100540083638509927396741802487875496","241996784243828715112683621079685224511","289735231494140392821617290262824326673","97950285867730060465213641024424361723","91325657800151498268561226358569129618","176049146906645793711834568023294815278","26560489141746959188457840323248191688","288193650944767960777594909763098798178"]}},{"id":"CVE-2026-33164-afbb2704","signature_version":"v1","target":{"file":"sherlock265/VideoDecoder.cc"},"source":"https://github.com/strukturag/libde265/commit/f3d916c8e63e510bda1f9cf5e8710259c22afece","deprecated":false,"signature_type":"Line","digest":{"threshold":0.9,"line_hashes":["156570059363990044612634730938499588619","18700694985350976804673429355869064680","50316390665775045091248204107304896162","326227675731134023503142758311502438721"]}},{"id":"CVE-2026-33164-fe0b8708","signature_version":"v1","target":{"file":"sherlock265/VideoDecoder.cc","function":"VideoDecoder::decoder_loop"},"source":"https://github.com/strukturag/libde265/commit/f3d916c8e63e510bda1f9cf5e8710259c22afece","deprecated":false,"signature_type":"Function","digest":{"function_hash":"257296791433569082839604763796126016482","length":812}}],"vanir_signatures_modified":"2026-04-12T20:14:10Z"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}]}