Notice USN-8815-1, published on September 24, 2026, describes four flaws in libass, a subtitle-processing library. Possible effects include a crash and, in some cases, arbitrary code execution when processing specific content.
CVE-2020-24994 concerns nested string parsing operations and affects Ubuntu 14.04, 16.04, 18.04, and 20.04 LTS. CVE-2020-26682 concerns certain outline-processing operations and affects Ubuntu 18.04 and 20.04 LTS; both can cause denial of service.
CVE-2026-61627 concerns ASS files and measuring broken lines, affecting Ubuntu 24.04 and 26.04 LTS. CVE-2026-61626 concerns Matroska subtitle segments with negative ReadOrder values and affects Ubuntu 26.04 LTS. These two flaws can cause a crash or possibly code execution.
To assess exposure, compare the Ubuntu version in use with those listed in the notice and consult the original Ubuntu Security publication by searching for USN-8815-1 and the CVE identifiers. Also check for security updates available for your system; do not assume a flaw is fixed without confirming the installed version and update status.
If you use AI to summarize the notice or support your analysis, avoid submitting internal data, credentials, or confidential subtitle files. Prefer public, anonymized excerpts, and verify technical recommendations against the original notice and system documentation.