A vulnerability described as critical has been identified in strukturag libde265 up to 1.0.16. Impacted is the function pic_parameter_set::set_derived_values. Executing a manipulation can lead to heap-based buffer overflow.

This vulnerability is handled as CVE-2026-33164. The attack can be executed remotely. There is not any exploit available.

Upgrading the affected component is recommended.