Skip to content
USN-8573-1: libde265 vulnerabilities

USN-8573-1: libde265 vulnerabilities

Ubuntu July 20, 2026

It was discovered that libde265 did not properly manage memory under certain circumstances. An attacker could possibly use this issue to cause libde265 to crash, resulting in a denial of service. This issue only affected Ubuntu 22.04 LTS. ( CVE-2023-51792 ) It was discovered that libde265 did not properly handle certain malformed media files, leading to a heap buffer overflow. An attacker could possibly use this issue to cause libde265 to crash, resulting in a denial of service. ( CVE-2024-38949 , CVE-2024-38950 ) It was discovered that libde265 did not properly handle certain malformed input, leading to a segmentation fault. An attacker could possibly use this issue to cause libde265 to crash, resulting in a denial of service. ( CVE-2025-61147 ) It was discovered that...

It was discovered that libde265 did not properly manage memory under certain circumstances. An attacker could possibly use this issue to cause libde265 to crash, resulting in a denial of service. This issue only affected Ubuntu 22.04 LTS. ( CVE-2023-51792 )

It was discovered that libde265 did not properly handle certain malformed media files, leading to a heap buffer overflow. An attacker could possibly use this issue to cause libde265 to crash, resulting in a denial of service. ( CVE-2024-38949 , CVE-2024-38950 )

It was discovered that libde265 did not properly handle certain malformed input, leading to a segmentation fault. An attacker could possibly use this issue to cause libde265 to crash, resulting in a denial of service. ( CVE-2025-61147 )

It was discovered that...

It was discovered that libde265 did not properly manage memory under certain circumstances. An attacker could possibly use this issue to cause libde265 to crash, resulting in a denial of service. This issue only affected Ubuntu 22.04 LTS. ( CVE-2023-51792 ) It was discovered that libde265 did not properly handle certain malformed media files, leading to a heap buffer overflow. An attacker could possibly use this issue to cause libde265 to crash, resulting in a denial of service. ( CVE-2024-38949 , CVE-2024-38950 ) It was discovered that libde265 did not properly handle certain malformed input, leading to a segmentation fault. An attacker could possibly use this issue to cause libde265 to crash, resulting in a denial of service. ( CVE-2025-61147 ) It was discovered that libde265 did not properly handle a malformed H.265 PPS NAL unit, leading to a segmentation fault. An attacker could possibly use this issue to cause libde265 to crash, resulting in a denial of service. ( CVE-2026-33164 ) It was discovered that libde265 did not properly handle certain crafted HEVC bitstreams, leading to an out-of-bounds write. An attacker could possibly use this issue to cause libde265 to crash, resulting in a denial of service. ( CVE-2026-33165 ) Valentin Mercier discovered that libde265 did not properly validate tile geometry when handling crafted media files, leading to an out-of-bounds read. An attacker could possibly use this issue to cause libde265 to crash, resulting in a denial of service, or to obtain sensitive information. ( CVE-2026-45382 ) It was discovered that libde265 did not properly validate certain values when decoding crafted media files, leading to an out-of-bounds read. An attacker could possibly use this issue to cause libde265 to crash, resulting in a denial of service, or to obtain sensitive information. ( CVE-2026-45383 ) Ying Dong discovered that libde265 did not properly validate reference picture set entries when handling a crafted H.265 bitstream, leading to an out-of-bounds write. An attacker could possibly use this issue to cause libde265 to crash, resulting in a denial of service, or possibly execute arbitrary code. ( CVE-2026-49295 ) Ying Dong discovered that libde265 did not properly manage memory when handling a crafted sequence of H.265 NAL units, leading to excessive memory consumption. An attacker could possibly use this issue to cause libde265 to use excessive resources, leading to a denial of service. ( CVE-2026-49337 ) Ying Dong discovered that libde265 did not properly handle certain crafted H.265 bitstreams with large dimensions, leading to a heap buffer overflow. An attacker could possibly use this issue to cause libde265 to crash, resulting in a denial of service, or possibly execute arbitrary code. ( CVE-2026-49346 ) It was discovered that libde265 did not properly handle certain crafted HEVC bitstreams with large dimensions, leading to an out-of-bounds read and write. An attacker could possibly use this issue to cause libde265 to crash, resulting in a denial of service, or possibly execute arbitrary code. ( CVE-2026-54240 ) It was discovered that libde265 did not properly handle certain crafted HEVC bitstreams with large dimensions, leading to a heap buffer overflow. An attacker could possibly use this issue to cause libde265 to crash, resulting in a denial of service, or possibly execute arbitrary code. ( CVE-2026-54241 )

It was discovered that libde265 did not properly manage memory under certain circumstances. An attacker could possibly use this issue to cause libde265 to crash, resulting in a denial of service. This issue only affected Ubuntu 22.04 LTS. ( CVE-2023-51792 )

It was discovered that libde265 did not properly handle certain malformed media files, leading to a heap buffer overflow. An attacker could possibly use this issue to cause libde265 to crash, resulting in a denial of service. ( CVE-2024-38949 , CVE-2024-38950 )

It was discovered that libde265 did not properly handle certain malformed input, leading to a segmentation fault. An attacker could possibly use this issue to cause libde265 to crash, resulting in a denial of service. ( CVE-2025-61147 )

It was discovered that libde265 did not properly handle a malformed H.265 PPS NAL unit, leading to a segmentation fault. An attacker could possibly use this issue to cause libde265 to crash, resulting in a denial of service. ( CVE-2026-33164 )

It was discovered that libde265 did not properly handle certain crafted HEVC bitstreams, leading to an out-of-bounds write. An attacker could possibly use this issue to cause libde265 to crash, resulting in a denial of service. ( CVE-2026-33165 )

Valentin Mercier discovered that libde265 did not properly validate tile geometry when handling crafted media files, leading to an out-of-bounds read. An attacker could possibly use this issue to cause libde265 to crash, resulting in a denial of service, or to obtain sensitive information. ( CVE-2026-45382 )

It was discovered that libde265 did not properly validate certain values when decoding crafted media files, leading to an out-of-bounds read. An attacker could possibly use this issue to cause libde265 to crash, resulting in a denial of service, or to obtain sensitive information. ( CVE-2026-45383 )

Ying Dong discovered that libde265 did not properly validate reference picture set entries when handling a crafted H.265 bitstream, leading to an out-of-bounds write. An attacker could possibly use this issue to cause libde265 to crash, resulting in a denial of service, or possibly execute arbitrary code. ( CVE-2026-49295 )

Ying Dong discovered that libde265 did not properly manage memory when handling a crafted sequence of H.265 NAL units, leading to excessive memory consumption. An attacker could possibly use this issue to cause libde265 to use excessive resources, leading to a denial of service. ( CVE-2026-49337 )

Ying Dong discovered that libde265 did not properly handle certain crafted H.265 bitstreams with large dimensions, leading to a heap buffer overflow. An attacker could possibly use this issue to cause libde265 to crash, resulting in a denial of service, or possibly execute arbitrary code. ( CVE-2026-49346 )

It was discovered that libde265 did not properly handle certain crafted HEVC bitstreams with large dimensions, leading to an out-of-bounds read and write. An attacker could possibly use this issue to cause libde265 to crash, resulting in a denial of service, or possibly execute arbitrary code. ( CVE-2026-54240 )

It was discovered that libde265 did not properly handle certain crafted HEVC bitstreams with large dimensions, leading to a heap buffer overflow. An attacker could possibly use this issue to cause libde265 to crash, resulting in a denial of service, or possibly execute arbitrary code. ( CVE-2026-54241 )

In general, a standard system update will make all the necessary changes.

The problem can be corrected by updating your system to the following package versions:

Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.