Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges

Alerts This Week
Warning Icon 1 485
Alerts This Week
Warning Icon 1 485

Ubuntu 8573-1 Libde265 Critical Denial of Service Vulnerabilities

ubuntu
Calendar Grey July 20, 2026
Scroller Ubuntu
Multiple security concerns addressed in the libde265 package for Ubuntu impacting stability and service availability.
Several security issues were fixed in libde265.

Summary

Several security issues were fixed in libde265.

Software Description:

- libde265: Open source implementation of the h.265 video codec

Details:

It was discovered that libde265 did not properly manage memory under

certain circumstances. An attacker could possibly use this issue to

cause libde265 to crash, resulting in a denial of service. This issue

only affected Ubuntu 22.04 LTS. (CVE-2023-51792)

It was discovered that libde265 did not properly handle certain

malformed media files, leading to a heap buffer overflow. An attacker

could possibly use this issue to cause libde265 to crash, resulting in

a denial of service. (CVE-2024-38949, CVE-2024-38950)

It was discovered that libde265 did not properly handle certain

malformed input, leading to a segmentation fault. An attacker could

possibly use this issue to cause libde265 to crash, resulting in a

denial of service. (CVE-2025-61147)

It was discovered that libde265 did not properly handle a malformed

H.265 PPS NAL unit, leading t...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 26.04 LTS
  libde265-0                      1.0.16-1ubuntu0.1~esm1
                                  Available with Ubuntu Pro
  libde265-dev                    1.0.16-1ubuntu0.1~esm1
                                  Available with Ubuntu Pro

Ubuntu 24.04 LTS
  libde265-0                      1.0.15-1ubuntu0.1
  libde265-dev                    1.0.15-1ubuntu0.1

Ubuntu 22.04 LTS
  libde265-0                      1.0.8-1ubuntu0.3+esm2
                                  Available with Ubuntu Pro
  libde265-dev                    1.0.8-1ubuntu0.3+esm2
                                  Available with Ubuntu Pro

Ubuntu 20.04 LTS
  libde265-0                      1.0.4-1ubuntu0.4+esm2
                                  Available with Ubuntu Pro
  libde265-dev                    1.0.4-1ubuntu0.4+esm2
                                  Available with Ubuntu Pro

Ubuntu 18.04 LTS
  libde265-0                      1.0.2-2ubuntu0.18.04.1~esm6
                                  Available with Ubuntu Pro
  libde265-dev                    1.0.2-2ubuntu0.18.04.1~esm6
                                  Available with Ubuntu Pro

Ubuntu 16.04 LTS
  libde265-0                      1.0.2-2ubuntu0.16.04.1~esm6
                                  Available with Ubuntu Pro
  libde265-dev                    1.0.2-2ubuntu0.16.04.1~esm6
                                  Available with Ubuntu Pro

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-8573-1

CVE-2024-38949, CVE-2024-38950, CVE-2025-61147, CVE-2026-33164,

CVE-2026-33165, CVE-2026-45382, CVE-2026-45383, CVE-2026-49295,

CVE-2026-49337, CVE-2026-49346, CVE-2026-54240, CVE-2026-54241

Severity
critical
Lowest
Low
Medium
High
Critical

Ubuntu Security Notice USN-8573-1

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.