Packages
- libde265 - Open source implementation of the h.265 video codec
Details
It was discovered that libde265 did not properly manage memory under
certain circumstances. An attacker could possibly use this issue to
cause libde265 to crash, resulting in a denial of service. This issue
only affected Ubuntu 22.04 LTS. (CVE-2023-51792)
It was discovered that libde265 did not properly handle certain
malformed media files, leading to a heap buffer overflow. An attacker
could possibly use this issue to cause libde265 to crash, resulting in
a denial of service. (CVE-2024-38949, CVE-2024-38950)
It was discovered that libde265 did not properly handle certain
malformed input, leading to a segmentation fault. An attacker could
possibly use this issue to cause libde265 to crash, resulting in a
denial of service. (CVE-2025-61147)
It was discovered that...
It was discovered that libde265 did not properly manage memory under
certain circumstances. An attacker could possibly use this issue to
cause libde265 to crash, resulting in a denial of service. This issue
only affected Ubuntu 22.04 LTS. (CVE-2023-51792)
It was discovered that libde265 did not properly handle certain
malformed media files, leading to a heap buffer overflow. An attacker
could possibly use this issue to cause libde265 to crash, resulting in
a denial of service. (CVE-2024-38949, CVE-2024-38950)
It was discovered that libde265 did not properly handle certain
malformed input, leading to a segmentation fault. An attacker could
possibly use this issue to cause libde265 to crash, resulting in a
denial of service. (CVE-2025-61147)
It was discovered that libde265 did not properly handle a malformed
H.265 PPS NAL unit, leading to a segmentation fault. An attacker could
possibly use this issue to cause libde265 to crash, resulting in a
denial of service. (CVE-2026-33164)
It was discovered that libde265 did not properly handle certain
crafted HEVC bitstreams, leading to an out-of-bounds write. An attacker
could possibly use this issue to cause libde265 to crash, resulting in
a denial of service. (CVE-2026-33165)
Valentin Mercier discovered that libde265 did not properly validate
tile geometry when handling crafted media files, leading to an
out-of-bounds read. An attacker could possibly use this issue to cause
libde265 to crash, resulting in a denial of service, or to obtain
sensitive information. (CVE-2026-45382)
It was discovered that libde265 did not properly validate certain
values when decoding crafted media files, leading to an out-of-bounds
read. An attacker could possibly use this issue to cause libde265 to
crash, resulting in a denial of service, or to obtain sensitive
information. (CVE-2026-45383)
Ying Dong discovered that libde265 did not properly validate reference
picture set entries when handling a crafted H.265 bitstream, leading to
an out-of-bounds write. An attacker could possibly use this issue to
cause libde265 to crash, resulting in a denial of service, or possibly
execute arbitrary code. (CVE-2026-49295)
Ying Dong discovered that libde265 did not properly manage memory when
handling a crafted sequence of H.265 NAL units, leading to excessive
memory consumption. An attacker could possibly use this issue to cause
libde265 to use excessive resources, leading to a denial of service.
(CVE-2026-49337)
Ying Dong discovered that libde265 did not properly handle certain
crafted H.265 bitstreams with large dimensions, leading to a heap
buffer overflow. An attacker could possibly use this issue to cause
libde265 to crash, resulting in a denial of service, or possibly
execute arbitrary code. (CVE-2026-49346)
It was discovered that libde265 did not properly handle certain crafted
HEVC bitstreams with large dimensions, leading to an out-of-bounds
read and write. An attacker could possibly use this issue to cause
libde265 to crash, resulting in a denial of service, or possibly
execute arbitrary code. (CVE-2026-54240)
It was discovered that libde265 did not properly handle certain crafted
HEVC bitstreams with large dimensions, leading to a heap buffer
overflow. An attacker could possibly use this issue to cause libde265
to crash, resulting in a denial of service, or possibly execute
arbitrary code. (CVE-2026-54241)
Update instructions
In general, a standard system update will make all the necessary changes.
Learn more about how to get the fixes.The problem can be corrected by updating your system to the following package versions:
| Ubuntu Release | Package Version | ||
|---|---|---|---|
| 26.04 LTS resolute | libde265-0 – 1.0.16-1ubuntu0.1~esm1 | ||
| libde265-dev – 1.0.16-1ubuntu0.1~esm1 | |||
| 24.04 LTS noble | libde265-0 – 1.0.15-1ubuntu0.1 | ||
| libde265-dev – 1.0.15-1ubuntu0.1 | |||
| 22.04 LTS jammy | libde265-0 – 1.0.8-1ubuntu0.3+esm2 | ||
| libde265-dev – 1.0.8-1ubuntu0.3+esm2 | |||
| 20.04 LTS focal | libde265-0 – 1.0.4-1ubuntu0.4+esm2 | ||
| libde265-dev – 1.0.4-1ubuntu0.4+esm2 | |||
| 18.04 LTS bionic | libde265-0 – 1.0.2-2ubuntu0.18.04.1~esm6 | ||
| libde265-dev – 1.0.2-2ubuntu0.18.04.1~esm6 | |||
| 16.04 LTS xenial | libde265-0 – 1.0.2-2ubuntu0.16.04.1~esm6 | ||
| libde265-dev – 1.0.2-2ubuntu0.16.04.1~esm6 | |||
Reduce your security exposure
Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.
References
- CVE-2026-54241
- CVE-2026-54240
- CVE-2026-49346
- CVE-2026-49337
- CVE-2026-49295
- CVE-2026-45383
- CVE-2026-45382
- CVE-2026-33165
- CVE-2026-33164
- CVE-2025-61147
- CVE-2026-54241
- CVE-2026-54240
- CVE-2026-49346
- CVE-2026-49337
- CVE-2026-49295
- CVE-2026-45383
- CVE-2026-45382
- CVE-2026-33165
- CVE-2026-33164
- CVE-2025-61147
- CVE-2024-38950
- CVE-2024-38949