+
+
Security Bulletin VLC 3.0.24
+
+
+Summary : Multiple vulnerabilities addressed in VLC media player 3.0.24
+Date : September 2026
+Affected versions : VLC media player 3.0.23 and earlier
+ID : VideoLAN-SB-VLC-3024
+CVE references : CVE-2026-56711, CVE-2026-73324
+
+
+
Details
+
+ VLC 3.0.24 fixes over 50 security issues in VLC itself. It also updates many bundled libraries, including FFmpeg, GnuTLS, libxml2 and libpng;
+ these updates include fixes for at least 74 publicly documented vulnerabilities.
+
+
+
Higher-impact issues:
+
+ - Heap buffer overflows in the TagLib metadata adapter when reading crafted media. (#30094)
+ - Integer overflows in picture allocation, leading to heap buffer overflows when processing images or subtitles. (#29692)
+ - A heap buffer overflow in WiDi LPCM audio decoding. (#29663)
+ - Out-of-bounds reads and writes when processing ARIB logo data in MPEG transport streams. (#29957)
+ - An integer overflow leading to a heap buffer overflow when reading metadata from a crafted VDR recording. (#29806)
+ - A path traversal when extracting a crafted skin archive, and a heap buffer overflow when loading a crafted skin.
+ - Disclosure of process memory to a SAT>IP server during session teardown. (#30072)
+ - Memory-safety issues in the legacy RealRTSP plugin, addressed by disabling the plugin in packaged builds. (#29956)
+
+
+
Additional fixes addressed:
+
+ - Buffer overflows and invalid memory accesses in Speex, ADPCM, G.711 and AAC decoding, and in FFmpeg audio channel handling.
+ - Invalid memory accesses in CEA-608 and CEA-708 captions, and DVD and CVD subtitles.
+ - Out-of-bounds accesses, a use-after-free and malformed-input handling in Matroska, Ogg, AVI, MP4, MPEG-TS, TiVo TY and image demuxers, and in MMS, Smooth Streaming and RIST handling.
+ - Disclosure of uninitialised memory in ASF and MPEG-TS stream output and raw-video RTP packets.
+ - Invalid memory accesses in CD-ROM and CUE sheet handling, and allocation overflows in OMX IL and JPEG/PNG encoding.
+ - FTP command injection through crafted URLs. (#30078)
+
+
+
Impact
+
These issues may cause crashes and memory disclosure with the user's privileges. Code execution has been demonstrated on macOS under specific conditions.
+
+
Threat mitigation
+
+ Crafted files or streams can trigger these issues during opening, metadata preparsing, or playlist processing.
+ Network and stream-output issues require the affected features to be in use.
+
+
+
Workarounds
+
Users who cannot upgrade yet should refrain from opening files or streams from untrusted sources.
+
+
Solution
+
Upgrade to VLC media player 3.0.24.
+
Distributors should apply the bundled-library updates or equivalent patches and keep RealRTSP disabled.
+
+
Support
+
VideoLAN thanks the Sovereign Tech Agency, and especially its Sovereign Tech Fund program, for supporting VLC's sustainability and safety.
+
+
Credits
+
+ - Thomas Guillem for finding issues in audio decoding, subtitles, demuxers, network input and stream output. (#29663, #29671, #29681, #29692, #29694, #29696, #29710, #29711, #30060, #30083, #30084, #30086)
+ - Fabian Wahle (Hap Security) for the SAT>IP disclosure and additional image-processing, RealRTSP and skin findings. (#30072, #29692, #29956, #29929; CVE-2026-56711, CVE-2026-73324)
+ - tedanvosin for the TagLib adapter report and additional ARIB logo impact analysis. (#30094, #29957)
+ - Kai Martin (KG3N Dynamics) for the ARIB logo and RealRTSP reports. (#29957, #29956)
+ - Khoka Moni for the VDR report. (#29806)
+ - Fran?ois Cartegnie for the Speex, CVD subtitle and CD-ROM findings. (#30103, #29864, #29863, #29862, #29859, #29858, #29857, #29856)
+ - tianshuo han for the TiVo TY, Matroska DVD menu, Ogg header handling and CEA-708 reports. (#29773, #29772, #29751, #29750)
+ - HE WEI (???) for the AVI subtitle, IMA/QuickTime ADPCM and G.711 reports. (#29972, #29971, #29969)
+ - Asif Nadaf for the Ogg Annodex, DVD SPU and TiVo TY reports. (#30045, #30046, #30044)
+ - Tristan Madani for the Ogg Skeleton and TiVo TY reports. (#29959, #29958)
+ - Brinly for the JPEG/PNG encoding and OMX IL reports. (#29720, #29719)
+ - Keno Hassler for the AAC channel-count report. (#30073)
+ - oxsignal for the MP4 CEA-608 report. (#29884)
+ - Alexandru Hossu for the Smooth Streaming report. (#29801)
+ - Aryan Chehreghani for the MMS report. (#29987)
+ - Trail of Bits for the cryptographic dependency report. (#29760)
+ - Cisco Talos for reporting the outdated FFmpeg dependency. (#29732)
+ - Mohammadmobinjavan (Ma3terPwner) and Adel Piri for the FTP command-injection report. (#30078)
+ - The upstream library maintainers and the VideoLAN contributors for their testing, reports and fixes.
+ - OSS-Fuzz for continuous fuzzing and issue reports throughout the release cycle. (#30080, #30037, #30024, #29954, #29895, #29893, #29887, #29879, #29852, #29837, #29835, #29834, #29832, #29831, #29822, #29808, #29807, #29800, #29781, #29776, #29756, #29728, #29686, #29677, #29670, #29657, #29636, #29634, #29578, #29565, #29561, #29560, #29546, #29541, #29521, #29518, #29517, #29449, #29446, #29444, #29321, #29289, #29227, #29223, #29057, #29001, #28991)
+
+
+
References
+
+ - The VideoLAN project
+ - https://www.videolan.org/
+ - VLC official Git repository
+ - https://code.videolan.org/videolan/vlc.git
+
+
+
+
+
View it on GitLab: https://code.videolan.org/VideoLAN.org/websites/-/commit/d7b119405b1db751ae1860057ed2a4c30d7ff638
--
View it on GitLab: https://code.videolan.org/VideoLAN.org/websites/-/commit/d7b119405b1db751ae1860057ed2a4c30d7ff638
You're receiving this email because of your account on code.videolan.org. Manage all notifications: https://code.videolan.org/-/profile/notifications | Help: https://code.videolan.org/help