From gitlab at videolan.org Thu Oct 1 12:08:40 2026 From: gitlab at videolan.org (Thomas Guillem (@tguillem)) Date: Thu, 01 Oct 2026 14:08:40 +0200 Subject: [www-doc] [Git][VideoLAN.org/websites] Pushed new branch sec-bulletin-24 Message-ID: <6abe4d4864fb3_14fd4398142101301559@gitlab.mail> Thomas Guillem pushed new branch sec-bulletin-24 at VideoLAN organization / websites -- View it on GitLab: https://code.videolan.org/VideoLAN.org/websites/-/tree/sec-bulletin-24 You're receiving this email because of your account on code.videolan.org. Manage all notifications: https://code.videolan.org/-/profile/notifications | Help: https://code.videolan.org/help From gitlab at videolan.org Thu Oct 1 12:10:17 2026 From: gitlab at videolan.org (Thomas Guillem (@tguillem)) Date: Thu, 01 Oct 2026 14:10:17 +0200 Subject: [www-doc] [Git][VideoLAN.org/websites][master] Add VLC 3.0.24 Security Bulletin Message-ID: <6abe4da9a4407_14fd4391d071413022ab@gitlab.mail> Thomas Guillem pushed to branch master at VideoLAN organization / websites Commits: d7b11940 by Thomas Guillem at 2026-10-01T14:08:25+02:00 Add VLC 3.0.24 Security Bulletin - - - - - 2 changed files: - www.videolan.org/security/index.php - + www.videolan.org/security/sb-vlc3024.php Changes: ===================================== www.videolan.org/security/index.php ===================================== @@ -19,6 +19,13 @@

VLC releases Security Bulletins (SB)

Those bulletins are related to each VLC release and can be made of multiple security issues, internal and external.

+

2026

+
+
VideoLAN-SB-VLC-324
+
Multiple vulnerabilities fixed in VLC media player 3.0.24 + Details +
+

2025

VideoLAN-SB-VLC-322
===================================== www.videolan.org/security/sb-vlc3024.php ===================================== @@ -0,0 +1,103 @@ + + + +
+ +

Security Bulletin VLC 3.0.24

+ +
+Summary           : Multiple vulnerabilities addressed in VLC media player 3.0.24
+Date              : September 2026
+Affected versions : VLC media player 3.0.23 and earlier
+ID                : VideoLAN-SB-VLC-3024
+CVE references    : CVE-2026-56711, CVE-2026-73324
+
+ +

Details

+

+ VLC 3.0.24 fixes over 50 security issues in VLC itself. It also updates many bundled libraries, including FFmpeg, GnuTLS, libxml2 and libpng; + these updates include fixes for at least 74 publicly documented vulnerabilities. +

+ +

Higher-impact issues:

+
    +
  • Heap buffer overflows in the TagLib metadata adapter when reading crafted media. (#30094)
  • +
  • Integer overflows in picture allocation, leading to heap buffer overflows when processing images or subtitles. (#29692)
  • +
  • A heap buffer overflow in WiDi LPCM audio decoding. (#29663)
  • +
  • Out-of-bounds reads and writes when processing ARIB logo data in MPEG transport streams. (#29957)
  • +
  • An integer overflow leading to a heap buffer overflow when reading metadata from a crafted VDR recording. (#29806)
  • +
  • A path traversal when extracting a crafted skin archive, and a heap buffer overflow when loading a crafted skin.
  • +
  • Disclosure of process memory to a SAT>IP server during session teardown. (#30072)
  • +
  • Memory-safety issues in the legacy RealRTSP plugin, addressed by disabling the plugin in packaged builds. (#29956)
  • +
+ +

Additional fixes addressed:

+
    +
  • Buffer overflows and invalid memory accesses in Speex, ADPCM, G.711 and AAC decoding, and in FFmpeg audio channel handling.
  • +
  • Invalid memory accesses in CEA-608 and CEA-708 captions, and DVD and CVD subtitles.
  • +
  • Out-of-bounds accesses, a use-after-free and malformed-input handling in Matroska, Ogg, AVI, MP4, MPEG-TS, TiVo TY and image demuxers, and in MMS, Smooth Streaming and RIST handling.
  • +
  • Disclosure of uninitialised memory in ASF and MPEG-TS stream output and raw-video RTP packets.
  • +
  • Invalid memory accesses in CD-ROM and CUE sheet handling, and allocation overflows in OMX IL and JPEG/PNG encoding.
  • +
  • FTP command injection through crafted URLs. (#30078)
  • +
+ +

Impact

+

These issues may cause crashes and memory disclosure with the user's privileges. Code execution has been demonstrated on macOS under specific conditions.

+ +

Threat mitigation

+

+ Crafted files or streams can trigger these issues during opening, metadata preparsing, or playlist processing. + Network and stream-output issues require the affected features to be in use. +

+ +

Workarounds

+

Users who cannot upgrade yet should refrain from opening files or streams from untrusted sources.

+ +

Solution

+

Upgrade to VLC media player 3.0.24.

+

Distributors should apply the bundled-library updates or equivalent patches and keep RealRTSP disabled.

+ +

Support

+

VideoLAN thanks the Sovereign Tech Agency, and especially its Sovereign Tech Fund program, for supporting VLC's sustainability and safety.

+ +

Credits

+
    +
  • Thomas Guillem for finding issues in audio decoding, subtitles, demuxers, network input and stream output. (#29663, #29671, #29681, #29692, #29694, #29696, #29710, #29711, #30060, #30083, #30084, #30086)
  • +
  • Fabian Wahle (Hap Security) for the SAT>IP disclosure and additional image-processing, RealRTSP and skin findings. (#30072, #29692, #29956, #29929; CVE-2026-56711, CVE-2026-73324)
  • +
  • tedanvosin for the TagLib adapter report and additional ARIB logo impact analysis. (#30094, #29957)
  • +
  • Kai Martin (KG3N Dynamics) for the ARIB logo and RealRTSP reports. (#29957, #29956)
  • +
  • Khoka Moni for the VDR report. (#29806)
  • +
  • Fran?ois Cartegnie for the Speex, CVD subtitle and CD-ROM findings. (#30103, #29864, #29863, #29862, #29859, #29858, #29857, #29856)
  • +
  • tianshuo han for the TiVo TY, Matroska DVD menu, Ogg header handling and CEA-708 reports. (#29773, #29772, #29751, #29750)
  • +
  • HE WEI (???) for the AVI subtitle, IMA/QuickTime ADPCM and G.711 reports. (#29972, #29971, #29969)
  • +
  • Asif Nadaf for the Ogg Annodex, DVD SPU and TiVo TY reports. (#30045, #30046, #30044)
  • +
  • Tristan Madani for the Ogg Skeleton and TiVo TY reports. (#29959, #29958)
  • +
  • Brinly for the JPEG/PNG encoding and OMX IL reports. (#29720, #29719)
  • +
  • Keno Hassler for the AAC channel-count report. (#30073)
  • +
  • oxsignal for the MP4 CEA-608 report. (#29884)
  • +
  • Alexandru Hossu for the Smooth Streaming report. (#29801)
  • +
  • Aryan Chehreghani for the MMS report. (#29987)
  • +
  • Trail of Bits for the cryptographic dependency report. (#29760)
  • +
  • Cisco Talos for reporting the outdated FFmpeg dependency. (#29732)
  • +
  • Mohammadmobinjavan (Ma3terPwner) and Adel Piri for the FTP command-injection report. (#30078)
  • +
  • The upstream library maintainers and the VideoLAN contributors for their testing, reports and fixes.
  • +
  • OSS-Fuzz for continuous fuzzing and issue reports throughout the release cycle. (#30080, #30037, #30024, #29954, #29895, #29893, #29887, #29879, #29852, #29837, #29835, #29834, #29832, #29831, #29822, #29808, #29807, #29800, #29781, #29776, #29756, #29728, #29686, #29677, #29670, #29657, #29636, #29634, #29578, #29565, #29561, #29560, #29546, #29541, #29521, #29518, #29517, #29449, #29446, #29444, #29321, #29289, #29227, #29223, #29057, #29001, #28991)
  • +
+ +

References

+
+
The VideoLAN project
+
https://www.videolan.org/
+
VLC official Git repository
+
https://code.videolan.org/videolan/vlc.git
+
+ +
+ + View it on GitLab: https://code.videolan.org/VideoLAN.org/websites/-/commit/d7b119405b1db751ae1860057ed2a4c30d7ff638 -- View it on GitLab: https://code.videolan.org/VideoLAN.org/websites/-/commit/d7b119405b1db751ae1860057ed2a4c30d7ff638 You're receiving this email because of your account on code.videolan.org. Manage all notifications: https://code.videolan.org/-/profile/notifications | Help: https://code.videolan.org/help