CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

USN-8573-1: libde265 vulnerabilities

unknownCVE-2023-51792CVE-2024-38949CVE-2024-38950CVE-2025-61147CVE-2026-33164CVE-2026-33165
It was discovered that libde265 did not properly manage memory under certain circumstances. An attacker could possibly use this issue to cause libde265 to crash, resulting in a denial of service. This issue only affected Ubuntu 22.04 LTS. (CVE-2023-51792) It was discovered that libde265 did not properly handle certain malformed media files, leading to a heap buffer overflow. An attacker could possibly use this issue to cause libde265 to crash, resulting in a denial of service. (CVE-2024-38949, CVE-2024-38950) It was discovered that libde265 did not properly handle certain malformed input, leading to a segmentation fault. An attacker could possibly use this issue to cause libde265 to crash, resulting in a denial of service. (CVE-2025-61147) It was discovered that libde265 did not properly handle a malformed H.265 PPS NAL unit, leading to a segmentation fault. An attacker could possibly use this issue to cause libde265 to crash, resulting in a denial of service. (CVE-2026-33164) It was discovered that libde265 did not properly handle certain crafted HEVC bitstreams, leading to an out-of-bounds write. An attacker could possibly use this issue to cause libde265 to crash, resulting in a denial of service. (CVE-2026-33165) Valentin Mercier discovered that libde265 did not properly validate tile geometry when handling crafted media files, leading to an out-of-bounds read. An attacker could possibly use this issue to cause libde265 to crash, resulting in a denial of service, or to obtain sensitive information. (CVE-2026-45382) It was discovered that libde265 did not properly validate certain values when decoding crafted media files, leading to an out-of-bounds read. An attacker could possibly use this issue to cause libde265 to crash, resulting in a denial of service, or to obtain sensitive information. (CVE-2026-45383) Ying Dong discovered that libde265 did not properly validate reference picture set entries when handling a crafted H.265 bitstream, leading to an out-of-bou

CSIRTS triage

What
Multiple vulnerabilities in libde265 could allow an attacker to cause the library to crash.
Who is affected
Users of libde265 on Ubuntu 22.04 LTS.
Urgency
Remediation is necessary as the vulnerabilities can lead to denial of service.
Action
Apply the latest patches for libde265 to address the vulnerabilities.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch libde265

Get an email when a new libde265 advisory drops — max one per day, one-click unsubscribe.

Details

Source
Ubuntu Security Notices (INTL · vendor-psirt · site)
Severity
unknown
Published
2026-07-20
Exploitation
Not in CISA KEV at last sync

Original advisory: https://ubuntu.com/security/notices/USN-8573-1

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2023-51792coverage & exploitation statusNVD · CVE.org
CVE-2024-38949coverage & exploitation statusNVD · CVE.org
CVE-2024-38950coverage & exploitation statusNVD · CVE.org
CVE-2025-61147coverage & exploitation statusNVD · CVE.org
CVE-2026-33164coverage & exploitation statusNVD · CVE.org
CVE-2026-33165coverage & exploitation statusNVD · CVE.org
CVE-2026-45382coverage & exploitation statusNVD · CVE.org
CVE-2026-45383coverage & exploitation statusNVD · CVE.org
CVE-2026-49295coverage & exploitation statusNVD · CVE.org
CVE-2026-49337coverage & exploitation statusNVD · CVE.org
CVE-2026-49346coverage & exploitation statusNVD · CVE.org
CVE-2026-54240coverage & exploitation statusNVD · CVE.org
CVE-2026-54241coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

More from Ubuntu Security Notices