CVE-2026-33165 | strukturag libde265 up to 1.0.16 Image Parser ctb_info.log2unitSize PicWidthInCtbsY/PicHeightInCtbsY out-of-bounds write (GHSA-653q-9f73-8hvg / EUVD-2026-13812)
A vulnerability labeled as critical has been found in strukturag libde265 up to 1.0.16. This vulnerability affects the function ctb_info.log2unitSize of the component Image Parser. Such manipulation of the argument PicWidthInCtbsY/PicHeightInCtbsY leads to out-of-bounds write.
This vulnerability is traded as CVE-2026-33165. The attack may be launched remotely. There is no exploit available.
The affected component should be upgraded.