Back to vendor advisories
Ubuntu Security NoticesUSN-8909-1

USN-8909-1: libde265 vulnerability

Severity not listed 0 CVEs Published Oct 8, 2026 at 5:11 PM UTC

Summary

It was discovered that libde265 did not properly validate certain crafted H.265 bitstreams, leading to a NULL pointer dereference. An attacker could possibly use this issue to cause libde265 to crash, resulting in a denial of service.

Products covered

A separate affected-products list was not included in the collected bulletin.

Remediation

Separate remediation guidance was not included in the collected bulletin.

CVEs in this advisory 0

No CVE identifiers were listed in the collected bulletin.

Updates

  1. Published by Ubuntu

    The publication date reported by the vendor.

  2. Added to SecurityAlert

    We collected the advisory from the official source.

  3. Confirmed at the source

    Our collector saw this advisory during a later source check.