Debian 12 libde265 Update Fixes 12 H.265 Decoder CVEs
Quick Answer
Debian published DLA-4789-1 for libde265 in Debian 12 bookworm. Version 1.0.11-1+deb12u3 fixes 12 CVEs plus two additional vulnerabilities that did not yet have CVE identifiers. Debian describes potential denial of service, heap or buffer overflows, information disclosure, code execution, and other impact.
Find Systems That Decode Untrusted H.265 Media
What to do now: Identify Debian 12 systems and services that use libde265, especially workloads that process untrusted HEVC media. Update through supported Debian repositories to 1.0.11-1+deb12u3 or a supported superseding release, restart dependent workloads where required, and validate the installed package and representative decoding paths.
Last verified: 2026-09-20 UTC. Recheck Debian's advisory and package repository before changing production.
Scope And Authority
| Product scope | Debian 12 bookworm libde265 package |
|---|---|
| Advisory | DLA-4789-1 |
| CVEs | CVE-2023-51792, CVE-2024-38949, CVE-2024-38950, CVE-2026-33164, CVE-2026-33165, CVE-2026-45382, CVE-2026-45383, CVE-2026-49295, CVE-2026-49337, CVE-2026-49346, CVE-2026-54240, CVE-2026-54241 |
| Additional identifiers | GHSA-xp3h-6f5r-8cxp and GHSA-mm7m-v26f-wf8x; Debian states that CVEs were not yet available |
| Authoritative release date | 2026-09-20 15:32:02 UTC |
| Authority revision date | 2026-09-20; initial advisory |
| Fixed version | 1.0.11-1+deb12u3 |
| CVSS base score | Not provided by the authority |
| CVSS severity | Not provided by the authority |
| Exploitation status | Not stated by Debian; no exploitation claim is inferred. |
What Debian Changed
The fixes address malformed H.265 or HEVC inputs that can reach decoder memory-safety and resource-management paths. Debian also lists a race-condition/use-after-free issue and a decoder reset use-after-free under GitHub identifiers because CVE IDs were not yet available. The advisory does not establish that every host or application using Debian 12 processes attacker-controlled video.
What To Validate Now
- Inventory. Locate Debian 12 bookworm systems with
libde265, including direct packages, transitive dependencies, image-processing services, media gateways, desktop applications, and containers. - Establish exposure. Confirm whether each workload decodes H.265 or HEVC content and whether untrusted users, files, messages, or network sources can reach that path.
- Remediate. Upgrade to
1.0.11-1+deb12u3through approved Debian repositories; rebuild immutable images and redeploy them where applicable. - Activate. Restart long-running services or applications that loaded the prior library, following the vendor-supported operational process.
- Validate. Confirm the installed package, active workload, representative media handling, logs, monitoring, and rollback readiness.
Operational Cautions
A package transaction alone does not prove that every container, image, or running process uses the fixed library. Test representative codecs and media workflows before broad deployment, and do not assign a CVSS score or exploitation status that Debian did not provide.
Evidence To Retain
- Asset, service, environment, and owner identifiers used for the applicability decision.
- UTC timestamps and before-and-after package, application, firmware, or build versions.
- Change approval, installation output, validation results, and any exception or rollback record.
- The authoritative advisory evidence used at the time of the decision.
Related TechGeeks Resources
Authoritative References
Correction policy: If Debian changes affected versions, fixed versions, severity, exploitation information, mitigations, or required action, TechGeeks will update this notice and its verification date.

