Junglewise Threat Intelligence

CVE-2026-49295: Strukturag libde265 out-of-bounds write in process_reference_picture_set

CVE-2026-49295 · Severity: high · CVSS 7.1 · Published 2026-06-19

Technologies: struktur AG Libde265. Vendors: Strukturag, struktur AG.

Executive brief

libde265 is an open-source library used by various applications to decode H.265 (HEVC) video files. A vulnerability in how the library handles specific video data structures allows an attacker to cause a crash or potentially execute unauthorized code by providing a specially crafted video file. This could lead to service disruptions or unauthorized access if a user opens a malicious video file in an affected application.

Technical details

An out-of-bounds write vulnerability exists in libde265 within the `decoder_context::process_reference_picture_set()` function in `decctx.cc`. The issue stems from a missing aggregate bound check when constructing predicted short-term reference picture sets (RPS). While individual list sizes are validated, the combined count of entries after predicted RPS construction can exceed the 16-entry limit of the `PocStFoll` array, leading to a write at index 16. An attacker can exploit this by providing a crafted H.265 bitstream with `inter_ref_pic_set_prediction_flag=1` that results in 17 entries. This is a remote attack vector requiring user interaction (opening a file) and can result in memory corruption, application crashes, or potential arbitrary code execution. The vulnerability is patched in version 1.0.20.

Affected products

  • strukturag libde265 < 1.0.20

Timeline

  • 2026-05-26: advisory: GitHub Security Advisory published
  • 2026-06-19: disclosed: NVD publication date
  • 2026-06-19: patched: Fix committed in version 1.0.20

References

Related threats