From gitlab at videolan.org Thu Oct 1 12:08:40 2026 From: gitlab at videolan.org (Thomas Guillem (@tguillem)) Date: Thu, 01 Oct 2026 14:08:40 +0200 Subject: [www-doc] [Git][VideoLAN.org/websites] Pushed new branch sec-bulletin-24 Message-ID: <6abe4d4864fb3_14fd4398142101301559@gitlab.mail> Thomas Guillem pushed new branch sec-bulletin-24 at VideoLAN organization / websites -- View it on GitLab: https://code.videolan.org/VideoLAN.org/websites/-/tree/sec-bulletin-24 You're receiving this email because of your account on code.videolan.org. Manage all notifications: https://code.videolan.org/-/profile/notifications | Help: https://code.videolan.org/help From gitlab at videolan.org Thu Oct 1 12:10:17 2026 From: gitlab at videolan.org (Thomas Guillem (@tguillem)) Date: Thu, 01 Oct 2026 14:10:17 +0200 Subject: [www-doc] [Git][VideoLAN.org/websites][master] Add VLC 3.0.24 Security Bulletin Message-ID: <6abe4da9a4407_14fd4391d071413022ab@gitlab.mail> Thomas Guillem pushed to branch master at VideoLAN organization / websites Commits: d7b11940 by Thomas Guillem at 2026-10-01T14:08:25+02:00 Add VLC 3.0.24 Security Bulletin - - - - - 2 changed files: - www.videolan.org/security/index.php - + www.videolan.org/security/sb-vlc3024.php Changes: ===================================== www.videolan.org/security/index.php ===================================== @@ -19,6 +19,13 @@
Those bulletins are related to each VLC release and can be made of multiple security issues, internal and external.
++Summary : Multiple vulnerabilities addressed in VLC media player 3.0.24 +Date : September 2026 +Affected versions : VLC media player 3.0.23 and earlier +ID : VideoLAN-SB-VLC-3024 +CVE references : CVE-2026-56711, CVE-2026-73324 ++ +
+ VLC 3.0.24 fixes over 50 security issues in VLC itself. It also updates many bundled libraries, including FFmpeg, GnuTLS, libxml2 and libpng; + these updates include fixes for at least 74 publicly documented vulnerabilities. +
+ +Higher-impact issues:
+Additional fixes addressed:
+These issues may cause crashes and memory disclosure with the user's privileges. Code execution has been demonstrated on macOS under specific conditions.
+ ++ Crafted files or streams can trigger these issues during opening, metadata preparsing, or playlist processing. + Network and stream-output issues require the affected features to be in use. +
+ +Users who cannot upgrade yet should refrain from opening files or streams from untrusted sources.
+ +Upgrade to VLC media player 3.0.24.
+Distributors should apply the bundled-library updates or equivalent patches and keep RealRTSP disabled.
+ +VideoLAN thanks the Sovereign Tech Agency, and especially its Sovereign Tech Fund program, for supporting VLC's sustainability and safety.
+ +I'm going to show my improvements to GDB. First, I'll demonstrate how to run Valgrind from inside GDB which makes Valgrind interactive instead of the static tool. Next, I'll introduce source-tracking breakpoints, an experimental tool I'm currently trying to add to GDB, which use saved source context to follow code changes after editing and rebuilding to adjust the breakpoints automatically. And finally, I'll be showing two experimental GDB Python commands that bring kernel information into a debugging session. drgn_why_sleeping uses drgn to inspect a thread's kernel stack and help understand what it is waiting for. ftrace-next records kernel function calls and return values while stepping over source code. I'll explain the current capabilities and limitations of my experiments.
+I am currently working at Red Hat, in the Linux kernel debugging team after several years developing GDB and Valgrind. My open-source background includes contributions to x264 and libvpx, I was working on SIMD optimizations for video codecs. My debugging work includes closer GDB?Valgrind integration, source-tracking breakpoints, and recent experiments connecting GDB with drgn and ftrace.
+Writing a video encoder usually takes months, not hours. In under twelve hours, I used Claude Code to build wav1c: a bare-bones spec-compliant AV1 encoder in pure Rust, with no dependencies. It decodes with dav1d and Apple's hardware decoder, plugs into FFmpeg, and runs in real time in the browser via WebAssembly.
+This talk is an honest account of how a former AI skeptic got there. It covers why standards documents plus an encode/decode verification loop suits agentic coding so well, where the agent needed steering, and what lower-cost custom codecs could mean for multimedia. You'll leave with practical patterns for using coding agents on complex, spec-driven work.
+Rafael Caricio is a Senior Software Engineer at Netflix with a long-running interest in multimedia technology, Rust, and open source.
+Via Salaria 113, 00198 Roma, Italy
+Meetups and unconferences will take place in Aula Alfa, Aula Portico and Aula Oriana, all located on the ground floor. You are also allowed to hangout in the outdoor courtyards!