Multiple Vulnerabilities in libde265 Affect Ubuntu 22.04 LTS

Multiple Vulnerabilities in libde265 Affect Ubuntu 22.04 LTS

First seen 21 Jul 2026, 09:36 UTC UbuntuLinuxsecurityubuntu.com 91% similarity 57.8

Article Content

Browse articles
ThreatCluster

Several vulnerabilities were discovered in libde265, the open-source H.265 video codec implementation, affecting Ubuntu 22.04 LTS. The issues include improper memory management, heap buffer overflows, and segmentation faults, which could lead to denial of service attacks. Specific CVEs include CVE-2023-51792, CVE-2024-38949, CVE-2024-38950, CVE-2025-61147, CVE-2026-33164, and CVE-2026-33165. These vulnerabilities allow attackers to exploit malformed media files and crafted HEVC bitstreams. The vulnerabilities were published between April 2024 and March 2026. Users are advised to update their systems to mitigate these risks. The current status is that patches are available for affected versions. The issues highlight the importance of maintaining software updates to prevent potential exploitation.

Key Points: • libde265 vulnerabilities could lead to denial of service on Ubuntu 22.04 LTS. • Key CVEs include CVE-2023-51792 and CVE-2026-33165, published between 2024 and 2026. • Patches are available, and users are urged to update their systems promptly.

ThreatCluster AI

Timeline

2024-04-19
CVE-2023-51792 published
Memory management issues in libde265 could lead to denial of service on Ubuntu 22.04 LTS.
Ubuntu
2024-06-26
CVE-2024-38949 and CVE-2024-38950 published
Heap buffer overflow vulnerabilities discovered in libde265, affecting Ubuntu 22.04 LTS.
Ubuntu
2026-02-23
CVE-2025-61147 published
Segmentation fault vulnerability identified in libde265, impacting Ubuntu 22.04 LTS.
Ubuntu
2026-03-20
CVE-2026-33164 and CVE-2026-33165 published
Out-of-bounds write and read vulnerabilities found in libde265, leading to potential denial of service.
Ubuntu
2026-06-19
CVE-2026-49295 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-19
CVE-2026-49337 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-19
CVE-2026-49346 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
Recent
Patches released for libde265 vulnerabilities
Users are urged to update their systems to the latest versions to mitigate the risks associated with these vulnerabilities.
Linuxsecurity

Community

Browse all →