← Back to blog

Ubuntu libde265 Vulnerabilities Expose Systems to DoS Attacks

Multiple flaws in Ubuntu's libde265 library could allow attackers to crash systems via malformed media files. All issues affect Ubuntu 22.04 LTS and require immediate patching.

TL;DR

  • Five vulnerabilities found in Ubuntu’s libde265 HEVC decoder library
  • All flaws can lead to denial of service through crafted media inputs
  • Affects Ubuntu 22.04 LTS only
  • Includes risks like heap buffer overflows and segmentation faults
  • Immediate update recommended to prevent potential system crashes

Ubuntu has disclosed multiple high-risk vulnerabilities in its libde265 library, which handles decoding for the H.265/HEVC video format. These flaws may allow attackers to trigger crashes or segmentation faults by submitting specially crafted media content.

The identified issues primarily result in denial of service (DoS), where an affected system could become unresponsive or require a restart. Users running Ubuntu 22.04 LTS are urged to apply updates as soon as possible to mitigate these threats.

Vulnerability Overview

  • CVE-2023-51792: Memory management flaw leads to application crash
  • CVE-2024-38949 & CVE-2024-38950: Heap buffer overflows from malformed files
  • CVE-2025-61147 & CVE-2026-33164: Segmentation faults caused by invalid input handling

Impact and Mitigation

  • All vulnerabilities affect Ubuntu 22.04 LTS exclusively
  • Exploitation can cause service disruption without authentication
  • No known active exploitation reported at this time
  • Users should upgrade packages using apt or their preferred update mechanism

Sources

Sources

Security email updates

One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.

Ubuntu libde265 Vulnerabilities Expose Systems to DoS Attacks — Agent Breach Blog | Agent Breach