{"id":"CVE-2026-88373","published":"2026-09-24T17:17:07.197","lastModified":"2026-09-25T18:17:31.937","description":"libde265 commit 4d45a6b contains a NULL pointer dereference vulnerability in the NAL parsing path. When de265_push_NAL() is called with a zero-length NAL unit, the resulting NAL_unit may retain a NULL backing buffer, which is subsequently passed as the destination argument to memcpy() in NAL_unit::set_data(). Although the copy length is zero, this violates the nonnull requirement of memcpy() and results in undefined behavior, causing process termination in UBSan-instrumented builds and denial of service.","cvssScore":7.5,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwes":["CWE-476"],"vendors":[],"products":[],"references":[{"url":"https://github.com/strukturag/libde265/commit/f8d324914e43d92af23614f22959cf9eee7bf9ea","tags":[]},{"url":"https://github.com/strukturag/libde265/issues/534","tags":[]},{"url":"https://github.com/strukturag/libde265/issues/534","tags":[]}],"exploitRefs":[{"url":"https://github.com/strukturag/libde265/commit/f8d324914e43d92af23614f22959cf9eee7bf9ea","tags":[]},{"url":"https://github.com/strukturag/libde265/issues/534","tags":[]},{"url":"https://github.com/strukturag/libde265/issues/534","tags":[]}],"hasPoc":true,"ai":null}