- What: A vulnerability in libvpx could allow a remote attacker to cause a denial of service or possibly execute arbitrary code.
- Impact: Applications using libvpx could be affected by opening a specially crafted file.
- Affected: Ubuntu 25.10, 24.04 LTS, and 22.04 LTS.
Ubuntu Security Notices USN-8053-1 USN-8053-1: libvpx vulnerability Publication date 19 February 2026 Overview libvpx could be made to crash or run programs if it opened a specially crafted file. Releases 25.10 24.04 LTS 22.04 LTS Packages libvpx - VP8 and VP9 video codec Details It was discovered that libvpx did not properly handle certain malformed media files. If an application using libvpx opened a specially crafted file, a remote attacker could cause a denial of service, or possibly execute arbitrary code. It was discovered that libvpx did not properly handle certain malformed media files. If an application using libvpx opened a specially crafted file, a remote attacker could cause a denial of service, or possibly execute arbitrary code. Update instructions In general, a standard system update will make all the necessary changes. Learn more about how to get the fixes. The problem can be corrected by updating your system to the following package versions: Ubuntu Release Package Version 25.10 questing libvpx9 – 1.15.0-2.1ubuntu0.1 24.04 LTS noble libvpx9 – 1.14.0-1ubuntu2.3 22.04 LTS jammy libvpx7 – 1.11.0-2ubuntu2.5 Reduce your security exposure Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines. Get Ubuntu Pro References CVE-2026-2447 CVE-2026-2447