USN-8909-1: libde265 vulnerability

Publication date

8 October 2026

Overview

libde265 could be made to crash if it received specially crafted input.


Packages

  • libde265 - Open source implementation of the h.265 video codec

Details

It was discovered that libde265 did not properly validate certain crafted
H.265 bitstreams, leading to a NULL pointer dereference. An attacker could
possibly use this issue to cause libde265 to crash, resulting in a denial
of service.

It was discovered that libde265 did not properly validate certain crafted
H.265 bitstreams, leading to a NULL pointer dereference. An attacker could
possibly use this issue to cause libde265 to crash, resulting in a denial
of service.

Update instructions

In general, a standard system update will make all the necessary changes.

Learn more about how to get the fixes.

The problem can be corrected by updating your system to the following package versions:

Ubuntu Release Package Version
26.04 LTS resolute libde265-0 –  1.0.16-1ubuntu0.1~esm2  
libde265-dev –  1.0.16-1ubuntu0.1~esm2  
24.04 LTS noble libde265-0 –  1.0.15-1ubuntu0.2
libde265-dev –  1.0.15-1ubuntu0.2
22.04 LTS jammy libde265-0 –  1.0.8-1ubuntu0.3+esm3  
libde265-dev –  1.0.8-1ubuntu0.3+esm3  
20.04 LTS focal libde265-0 –  1.0.4-1ubuntu0.4+esm3  
libde265-dev –  1.0.4-1ubuntu0.4+esm3  
18.04 LTS bionic libde265-0 –  1.0.2-2ubuntu0.18.04.1~esm7  
libde265-dev –  1.0.2-2ubuntu0.18.04.1~esm7  
16.04 LTS xenial libde265-0 –  1.0.2-2ubuntu0.16.04.1~esm7
libde265-dev –  1.0.2-2ubuntu0.16.04.1~esm7

Reduce your security exposure

Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.


Have additional questions?

Talk to a member of the team ›