CVE-2026-49295: bound aggregate short-term RPS size
Origin: upstream, https://github.com/strukturag/libde265/commit/
691f3a3c55b3d32478c4a49895dee061a282652b
Bug: https://github.com/strukturag/libde265/security/advisories/GHSA-g2rg-wj66-w594
Bug-Debian: https://bugs.debian.org/
1140431
Applied-Upstream: 1.1.0
Missing aggregate bound check on predicted reference picture set entries
allows exceeding the 16-entry array, an out-of-bounds array write in
process_reference_picture_set().
Gbp-Pq: Name CVE-2026-49295.patch