USN-8909-1: libde265 vulnerability
AI summary · grok-4.7
Ubuntu warns libde265 can crash on crafted H.265 bitstreams via a NULL pointer dereference.
Ubuntu Security Notice USN-8909-1 reports that libde265 did not properly validate certain crafted H.265 bitstreams, causing a NULL pointer dereference. An attacker could use a malicious bitstream to crash libde265 and cause a denial of service. The notice does not cite a CVE identifier or report observed exploitation.
- libde265 fails to validate certain crafted H.265 bitstreams.
- The flaw is a NULL pointer dereference that can crash the library.
- Impact is denial of service; no exploitation in the wild is reported.
Full article
It was discovered that libde265 did not properly validate certain crafted H.265 bitstreams, leading to a NULL pointer dereference. An attacker could possibly use this issue to cause libde265 to crash, resulting in a denial of service.
This source does not provide full text. Read it at ubuntu.com.