News

USN-8909-1: libde265 flaw risks crashes with malformed H.265 bitstreams

Ubuntu fixes a DoS vulnerability in libde265 (CVE-2026-88373): malformed H.265 bitstreams trigger a NULL pointer dereference.

UptimeMag editorial team · 9 October 2026 · 1 min read

USN-8909-1: falla in libde265, rischio crash con bitstream H.265 malformati

Ubuntu published the USN-8909-1 security notice for libde265 on 8 October 2026, the open-source library that implements the H.265 video codec. The flaw, identified as CVE-2026-88373, affects anyone running server services that decode H.265 content, from transcoders to media processing systems.

The problem

According to the official advisory, libde265 does not correctly validate certain specially crafted H.265 bitstreams, causing a NULL pointer dereference. An attacker can exploit this flaw to crash the library, resulting in a denial of service on the process using it.

Affected packages and fixed versions

The flaw affects the libde265-0 and libde265-dev packages across all still-supported LTS releases:

Ubuntu release Code name Fixed version Channel
26.04 LTS resolute 1.0.16-1ubuntu0.1~esm2 Ubuntu Pro (ESM Apps)
24.04 LTS noble 1.0.15-1ubuntu0.2 Standard repository
22.04 LTS jammy 1.0.8-1ubuntu0.3+esm3 Ubuntu Pro (ESM Apps)
20.04 LTS focal 1.0.4-1ubuntu0.4+esm3 Ubuntu Pro (ESM Apps)
18.04 LTS bionic 1.0.2-2ubuntu0.18.04.1~esm7 Ubuntu Pro (ESM Apps)
16.04 LTS xenial 1.0.2-2ubuntu0.16.04.1~esm7 Ubuntu Pro (ESM Apps)

Only on 24.04 LTS is the fix available via a regular system update. On all other releases, including 26.04 and 22.04, the fixed package requires an Ubuntu Pro subscription via ESM Apps: Ubuntu notes that a public fix for these versions may arrive in future, but it is not currently available outside ESM.

What to do

On systems using the standard repositories, a simple system update is enough to apply the fix where available. Anyone managing machines on releases other than 24.04 LTS who wants the fixed package needs to check their Ubuntu Pro coverage, which is free for up to 5 machines as stated in the advisory itself.

Full reference details and update instructions are available on the official USN-8909-1 advisory page at ubuntu.com/security/notices.

Written with the help of artificial intelligence and checked by the editors (EU AI Act, art. 50). Source: Ubuntu – avvisi di sicurezza.