OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-88373

HIGH · CVSS 7.5 EPSS 0.34% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-24 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

A NULL pointer dereference vulnerability exists in the NAL parsing path of libde265, specifically triggered when de265_push_NAL() processes a zero-length NAL unit. This flaw can lead to undefined behavior, including process termination and denial of service, particularly in environments using UBSan instrumentation. Developers and organizations utilizing libde265 should prioritize addressing this vulnerability to mitigate potential service disruptions.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-88373
Severity
HIGH
CVSS
7.5
EPSS
0.34%

Original NVD Description

libde265 commit 4d45a6b contains a NULL pointer dereference vulnerability in the NAL parsing path. When de265_push_NAL() is called with a zero-length NAL unit, the resulting NAL_unit may retain a NULL backing buffer, which is subsequently passed as the destination argument to memcpy() in NAL_unit::set_data(). Although the copy length is zero, this violates the nonnull requirement of memcpy() and results in undefined behavior, causing process termination in UBSan-instrumented builds and denial of service.