USN-8909-1: libde265 flaw risks crashes with malformed H.265 bitstreams
Ubuntu fixes a DoS vulnerability in libde265 (CVE-2026-88373): malformed H.265 bitstreams trigger a NULL pointer dereference.
UptimeMag editorial team · 9 October 2026 · 1 min read

Ubuntu published the USN-8909-1 security notice for libde265 on 8 October 2026, the open-source library that implements the H.265 video codec. The flaw, identified as CVE-2026-88373, affects anyone running server services that decode H.265 content, from transcoders to media processing systems.
The problem
According to the official advisory, libde265 does not correctly validate certain specially crafted H.265 bitstreams, causing a NULL pointer dereference. An attacker can exploit this flaw to crash the library, resulting in a denial of service on the process using it.
Affected packages and fixed versions
The flaw affects the libde265-0 and libde265-dev packages across all still-supported LTS releases:
| Ubuntu release | Code name | Fixed version | Channel |
|---|---|---|---|
| 26.04 LTS | resolute | 1.0.16-1ubuntu0.1~esm2 | Ubuntu Pro (ESM Apps) |
| 24.04 LTS | noble | 1.0.15-1ubuntu0.2 | Standard repository |
| 22.04 LTS | jammy | 1.0.8-1ubuntu0.3+esm3 | Ubuntu Pro (ESM Apps) |
| 20.04 LTS | focal | 1.0.4-1ubuntu0.4+esm3 | Ubuntu Pro (ESM Apps) |
| 18.04 LTS | bionic | 1.0.2-2ubuntu0.18.04.1~esm7 | Ubuntu Pro (ESM Apps) |
| 16.04 LTS | xenial | 1.0.2-2ubuntu0.16.04.1~esm7 | Ubuntu Pro (ESM Apps) |
Only on 24.04 LTS is the fix available via a regular system update. On all other releases, including 26.04 and 22.04, the fixed package requires an Ubuntu Pro subscription via ESM Apps: Ubuntu notes that a public fix for these versions may arrive in future, but it is not currently available outside ESM.
What to do
On systems using the standard repositories, a simple system update is enough to apply the fix where available. Anyone managing machines on releases other than 24.04 LTS who wants the fixed package needs to check their Ubuntu Pro coverage, which is free for up to 5 machines as stated in the advisory itself.
Full reference details and update instructions are available on the official USN-8909-1 advisory page at ubuntu.com/security/notices.
Written with the help of artificial intelligence and checked by the editors (EU AI Act, art. 50). Source: Ubuntu – avvisi di sicurezza.