How a stale metadata field became a heap buffer overflow
CVE-2026-33165: a heap out-of-bounds write in libde265 caused by a stale CTB size field surviving an SPS switch.
CVE-2026-33165: a heap out-of-bounds write in libde265 caused by a stale CTB size field surviving an SPS switch.