CVE-2026-33164

Source
https://cve.org/CVERecord?id=CVE-2026-33164
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-33164.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-33164
Aliases
  • GHSA-wqrf-6rf5-v78r
Downstream
Published
2026-03-20T20:33:04.054Z
Modified
2026-04-12T20:14:10.279869Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
NULL Pointer Dereference in libde265
Details

libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.17, a malformed H.265 PPS NAL unit causes a segmentation fault in picparameterset::setderivedvalues(). This issue has been patched in version 1.0.17.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/33xxx/CVE-2026-33164.json",
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-122"
    ]
}
References

Affected packages

Git / github.com/strukturag/libde265

Affected ranges

Type
GIT
Repo
https://github.com/strukturag/libde265
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

v0.*
v0.1
v0.2
v0.3
v0.4
v0.5
v1.*
v1.0.0
v1.0.10
v1.0.11
v1.0.12
v1.0.13
v1.0.14
v1.0.15
v1.0.16
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.0.7
v1.0.8
v1.0.9

Database specific

vanir_signatures
[
    {
        "digest": {
            "function_hash": "224189621832908547208584845959293867245",
            "length": 564.0
        },
        "id": "CVE-2026-33164-388c898b",
        "signature_type": "Function",
        "source": "https://github.com/strukturag/libde265/commit/f3d916c8e63e510bda1f9cf5e8710259c22afece",
        "deprecated": false,
        "target": {
            "function": "VideoWidget::paintEvent",
            "file": "sherlock265/VideoWidget.cc"
        },
        "signature_version": "v1"
    },
    {
        "digest": {
            "function_hash": "327840637841273794815898644878905505991",
            "length": 364.0
        },
        "id": "CVE-2026-33164-6ee60a4c",
        "signature_type": "Function",
        "source": "https://github.com/strukturag/libde265/commit/f3d916c8e63e510bda1f9cf5e8710259c22afece",
        "deprecated": false,
        "target": {
            "function": "VideoWidget::VideoWidget",
            "file": "sherlock265/VideoWidget.cc"
        },
        "signature_version": "v1"
    },
    {
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "24195985884818460783815628466886685969",
                "147038544006205557352957683921935214158",
                "332270579816490930149395567689058003278",
                "261987140283495801479336438506181096998",
                "434014289267642594433253264005132899",
                "168652729852070854314972564615697156958",
                "118537600665570856582955531051773423212",
                "331797459368371019932686990456084375128",
                "130059418393864323628047821926512668",
                "52533368177343838076000847856234591642",
                "281675411347226717154703759322655818114",
                "41100540083638509927396741802487875496",
                "241996784243828715112683621079685224511",
                "289735231494140392821617290262824326673",
                "97950285867730060465213641024424361723",
                "91325657800151498268561226358569129618",
                "176049146906645793711834568023294815278",
                "26560489141746959188457840323248191688",
                "288193650944767960777594909763098798178"
            ]
        },
        "id": "CVE-2026-33164-99af71a4",
        "signature_type": "Line",
        "source": "https://github.com/strukturag/libde265/commit/f3d916c8e63e510bda1f9cf5e8710259c22afece",
        "deprecated": false,
        "target": {
            "file": "sherlock265/VideoWidget.cc"
        },
        "signature_version": "v1"
    },
    {
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "156570059363990044612634730938499588619",
                "18700694985350976804673429355869064680",
                "50316390665775045091248204107304896162",
                "326227675731134023503142758311502438721"
            ]
        },
        "id": "CVE-2026-33164-afbb2704",
        "signature_type": "Line",
        "source": "https://github.com/strukturag/libde265/commit/f3d916c8e63e510bda1f9cf5e8710259c22afece",
        "deprecated": false,
        "target": {
            "file": "sherlock265/VideoDecoder.cc"
        },
        "signature_version": "v1"
    },
    {
        "digest": {
            "function_hash": "257296791433569082839604763796126016482",
            "length": 812.0
        },
        "id": "CVE-2026-33164-fe0b8708",
        "signature_type": "Function",
        "source": "https://github.com/strukturag/libde265/commit/f3d916c8e63e510bda1f9cf5e8710259c22afece",
        "deprecated": false,
        "target": {
            "function": "VideoDecoder::decoder_loop",
            "file": "sherlock265/VideoDecoder.cc"
        },
        "signature_version": "v1"
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-33164.json"
vanir_signatures_modified
"2026-04-12T20:14:10Z"