From gitlab at videolan.org Thu Oct 1 12:08:40 2026 From: gitlab at videolan.org (Thomas Guillem (@tguillem)) Date: Thu, 01 Oct 2026 14:08:40 +0200 Subject: [www-doc] [Git][VideoLAN.org/websites] Pushed new branch sec-bulletin-24 Message-ID: <6abe4d4864fb3_14fd4398142101301559@gitlab.mail> Thomas Guillem pushed new branch sec-bulletin-24 at VideoLAN organization / websites -- View it on GitLab: https://code.videolan.org/VideoLAN.org/websites/-/tree/sec-bulletin-24 You're receiving this email because of your account on code.videolan.org. Manage all notifications: https://code.videolan.org/-/profile/notifications | Help: https://code.videolan.org/help From gitlab at videolan.org Thu Oct 1 12:10:17 2026 From: gitlab at videolan.org (Thomas Guillem (@tguillem)) Date: Thu, 01 Oct 2026 14:10:17 +0200 Subject: [www-doc] [Git][VideoLAN.org/websites][master] Add VLC 3.0.24 Security Bulletin Message-ID: <6abe4da9a4407_14fd4391d071413022ab@gitlab.mail> Thomas Guillem pushed to branch master at VideoLAN organization / websites Commits: d7b11940 by Thomas Guillem at 2026-10-01T14:08:25+02:00 Add VLC 3.0.24 Security Bulletin - - - - - 2 changed files: - www.videolan.org/security/index.php - + www.videolan.org/security/sb-vlc3024.php Changes: ===================================== www.videolan.org/security/index.php ===================================== @@ -19,6 +19,13 @@

VLC releases Security Bulletins (SB)

Those bulletins are related to each VLC release and can be made of multiple security issues, internal and external.

+

2026

+
+
VideoLAN-SB-VLC-324
+
Multiple vulnerabilities fixed in VLC media player 3.0.24 + Details +
+

2025

VideoLAN-SB-VLC-322
===================================== www.videolan.org/security/sb-vlc3024.php ===================================== @@ -0,0 +1,103 @@ + + + +
+ +

Security Bulletin VLC 3.0.24

+ +
+Summary           : Multiple vulnerabilities addressed in VLC media player 3.0.24
+Date              : September 2026
+Affected versions : VLC media player 3.0.23 and earlier
+ID                : VideoLAN-SB-VLC-3024
+CVE references    : CVE-2026-56711, CVE-2026-73324
+
+ +

Details

+

+ VLC 3.0.24 fixes over 50 security issues in VLC itself. It also updates many bundled libraries, including FFmpeg, GnuTLS, libxml2 and libpng; + these updates include fixes for at least 74 publicly documented vulnerabilities. +

+ +

Higher-impact issues:

+
    +
  • Heap buffer overflows in the TagLib metadata adapter when reading crafted media. (#30094)
  • +
  • Integer overflows in picture allocation, leading to heap buffer overflows when processing images or subtitles. (#29692)
  • +
  • A heap buffer overflow in WiDi LPCM audio decoding. (#29663)
  • +
  • Out-of-bounds reads and writes when processing ARIB logo data in MPEG transport streams. (#29957)
  • +
  • An integer overflow leading to a heap buffer overflow when reading metadata from a crafted VDR recording. (#29806)
  • +
  • A path traversal when extracting a crafted skin archive, and a heap buffer overflow when loading a crafted skin.
  • +
  • Disclosure of process memory to a SAT>IP server during session teardown. (#30072)
  • +
  • Memory-safety issues in the legacy RealRTSP plugin, addressed by disabling the plugin in packaged builds. (#29956)
  • +
+ +

Additional fixes addressed:

+
    +
  • Buffer overflows and invalid memory accesses in Speex, ADPCM, G.711 and AAC decoding, and in FFmpeg audio channel handling.
  • +
  • Invalid memory accesses in CEA-608 and CEA-708 captions, and DVD and CVD subtitles.
  • +
  • Out-of-bounds accesses, a use-after-free and malformed-input handling in Matroska, Ogg, AVI, MP4, MPEG-TS, TiVo TY and image demuxers, and in MMS, Smooth Streaming and RIST handling.
  • +
  • Disclosure of uninitialised memory in ASF and MPEG-TS stream output and raw-video RTP packets.
  • +
  • Invalid memory accesses in CD-ROM and CUE sheet handling, and allocation overflows in OMX IL and JPEG/PNG encoding.
  • +
  • FTP command injection through crafted URLs. (#30078)
  • +
+ +

Impact

+

These issues may cause crashes and memory disclosure with the user's privileges. Code execution has been demonstrated on macOS under specific conditions.

+ +

Threat mitigation

+

+ Crafted files or streams can trigger these issues during opening, metadata preparsing, or playlist processing. + Network and stream-output issues require the affected features to be in use. +

+ +

Workarounds

+

Users who cannot upgrade yet should refrain from opening files or streams from untrusted sources.

+ +

Solution

+

Upgrade to VLC media player 3.0.24.

+

Distributors should apply the bundled-library updates or equivalent patches and keep RealRTSP disabled.

+ +

Support

+

VideoLAN thanks the Sovereign Tech Agency, and especially its Sovereign Tech Fund program, for supporting VLC's sustainability and safety.

+ +

Credits

+
    +
  • Thomas Guillem for finding issues in audio decoding, subtitles, demuxers, network input and stream output. (#29663, #29671, #29681, #29692, #29694, #29696, #29710, #29711, #30060, #30083, #30084, #30086)
  • +
  • Fabian Wahle (Hap Security) for the SAT>IP disclosure and additional image-processing, RealRTSP and skin findings. (#30072, #29692, #29956, #29929; CVE-2026-56711, CVE-2026-73324)
  • +
  • tedanvosin for the TagLib adapter report and additional ARIB logo impact analysis. (#30094, #29957)
  • +
  • Kai Martin (KG3N Dynamics) for the ARIB logo and RealRTSP reports. (#29957, #29956)
  • +
  • Khoka Moni for the VDR report. (#29806)
  • +
  • Fran?ois Cartegnie for the Speex, CVD subtitle and CD-ROM findings. (#30103, #29864, #29863, #29862, #29859, #29858, #29857, #29856)
  • +
  • tianshuo han for the TiVo TY, Matroska DVD menu, Ogg header handling and CEA-708 reports. (#29773, #29772, #29751, #29750)
  • +
  • HE WEI (???) for the AVI subtitle, IMA/QuickTime ADPCM and G.711 reports. (#29972, #29971, #29969)
  • +
  • Asif Nadaf for the Ogg Annodex, DVD SPU and TiVo TY reports. (#30045, #30046, #30044)
  • +
  • Tristan Madani for the Ogg Skeleton and TiVo TY reports. (#29959, #29958)
  • +
  • Brinly for the JPEG/PNG encoding and OMX IL reports. (#29720, #29719)
  • +
  • Keno Hassler for the AAC channel-count report. (#30073)
  • +
  • oxsignal for the MP4 CEA-608 report. (#29884)
  • +
  • Alexandru Hossu for the Smooth Streaming report. (#29801)
  • +
  • Aryan Chehreghani for the MMS report. (#29987)
  • +
  • Trail of Bits for the cryptographic dependency report. (#29760)
  • +
  • Cisco Talos for reporting the outdated FFmpeg dependency. (#29732)
  • +
  • Mohammadmobinjavan (Ma3terPwner) and Adel Piri for the FTP command-injection report. (#30078)
  • +
  • The upstream library maintainers and the VideoLAN contributors for their testing, reports and fixes.
  • +
  • OSS-Fuzz for continuous fuzzing and issue reports throughout the release cycle. (#30080, #30037, #30024, #29954, #29895, #29893, #29887, #29879, #29852, #29837, #29835, #29834, #29832, #29831, #29822, #29808, #29807, #29800, #29781, #29776, #29756, #29728, #29686, #29677, #29670, #29657, #29636, #29634, #29578, #29565, #29561, #29560, #29546, #29541, #29521, #29518, #29517, #29449, #29446, #29444, #29321, #29289, #29227, #29223, #29057, #29001, #28991)
  • +
+ +

References

+
+
The VideoLAN project
+
https://www.videolan.org/
+
VLC official Git repository
+
https://code.videolan.org/videolan/vlc.git
+
+ +
+ + View it on GitLab: https://code.videolan.org/VideoLAN.org/websites/-/commit/d7b119405b1db751ae1860057ed2a4c30d7ff638 -- View it on GitLab: https://code.videolan.org/VideoLAN.org/websites/-/commit/d7b119405b1db751ae1860057ed2a4c30d7ff638 You're receiving this email because of your account on code.videolan.org. Manage all notifications: https://code.videolan.org/-/profile/notifications | Help: https://code.videolan.org/help From gitlab at videolan.org Tue Oct 6 11:59:33 2026 From: gitlab at videolan.org (Vibhoothi (@mindfreeze)) Date: Tue, 06 Oct 2026 13:59:33 +0200 Subject: [www-doc] [Git][VideoLAN.org/websites][master] vdd26: Update schedule Message-ID: <6ac4e2a53d4aa_14fd4310a76d442169370@gitlab.mail> Vibhoothi pushed to branch master at VideoLAN organization / websites Commits: 7457b646 by vibhoothi at 2026-10-06T12:58:48+01:00 vdd26: Update schedule - - - - - 1 changed file: - www.videolan.org/videolan/events/vdd26/index.php Changes: ===================================== www.videolan.org/videolan/events/vdd26/index.php ===================================== @@ -442,7 +442,7 @@

12:10 - 12:25

-

Handling VLC Security Issues with Claudex, with a RCE case study

+

Handling VLC Security Issues with LLMs, Including an RCE Case Study

Thomas Guillem (VideoLAN)

Abstract & speaker @@ -664,8 +664,16 @@

11:35 - 11:55

-

TBD

-

TBD

+

Extending GDB for Multimedia Developers

+

Alexandra Petlanova Hajkova

+
+ Abstract & speaker +
+

I'm going to show my improvements to GDB. First, I'll demonstrate how to run Valgrind from inside GDB which makes Valgrind interactive instead of the static tool. Next, I'll introduce source-tracking breakpoints, an experimental tool I'm currently trying to add to GDB, which use saved source context to follow code changes after editing and rebuilding to adjust the breakpoints automatically. And finally, I'll be showing two experimental GDB Python commands that bring kernel information into a debugging session. drgn_why_sleeping uses drgn to inspect a thread's kernel stack and help understand what it is waiting for. ftrace-next records kernel function calls and return values while stepping over source code. I'll explain the current capabilities and limitations of my experiments.

+
About the speaker
+

I am currently working at Red Hat, in the Linux kernel debugging team after several years developing GDB and Valgrind. My open-source background includes contributions to x264 and libvpx, I was working on SIMD optimizations for video codecs. My debugging work includes closer GDB?Valgrind integration, source-tracking breakpoints, and recent experiments connecting GDB with drgn and ftrace.

+
+
View it on GitLab: https://code.videolan.org/VideoLAN.org/websites/-/commit/7457b6461ab8b1ed1355faaa120e3b41b3d45fd0 -- View it on GitLab: https://code.videolan.org/VideoLAN.org/websites/-/commit/7457b6461ab8b1ed1355faaa120e3b41b3d45fd0 You're receiving this email because of your account on code.videolan.org. Manage all notifications: https://code.videolan.org/-/profile/notifications | Help: https://code.videolan.org/help From gitlab at videolan.org Wed Oct 7 10:08:14 2026 From: gitlab at videolan.org (Vibhoothi (@mindfreeze)) Date: Wed, 07 Oct 2026 12:08:14 +0200 Subject: [www-doc] [Git][VideoLAN.org/websites][master] vdd26: Add another talk to AI session, and classrooms Message-ID: <6ac61a0ed7c72_14fd43122d131c230786f@gitlab.mail> Vibhoothi pushed to branch master at VideoLAN organization / websites Commits: 5acac032 by vibhoothi at 2026-10-07T11:07:31+01:00 vdd26: Add another talk to AI session, and classrooms - - - - - 1 changed file: - www.videolan.org/videolan/events/vdd26/index.php Changes: ===================================== www.videolan.org/videolan/events/vdd26/index.php ===================================== @@ -400,8 +400,17 @@

11:25 - 11:40

-

TBD

-

TBD

+

An AV1 Encoder in a Day: What Spec-Driven Agentic Coding Can Actually Do

+

Rafael Caricio (Netflix)

+
+ Abstract & speaker +
+

Writing a video encoder usually takes months, not hours. In under twelve hours, I used Claude Code to build wav1c: a bare-bones spec-compliant AV1 encoder in pure Rust, with no dependencies. It decodes with dav1d and Apple's hardware decoder, plugs into FFmpeg, and runs in real time in the browser via WebAssembly.

+

This talk is an honest account of how a former AI skeptic got there. It covers why standards documents plus an encode/decode verification loop suits agentic coding so well, where the agent needed steering, and what lower-cost custom codecs could mean for multimedia. You'll leave with practical patterns for using coding agents on complex, spec-driven work.

+
About the speaker
+

Rafael Caricio is a Senior Software Engineer at Netflix with a long-running interest in multimedia technology, Rust, and open source.

+
+
@@ -480,7 +489,7 @@

12:35 - 12:55

-

Community Day

+

Community Day Updates and Results

Jean-Baptiste Kempf (VideoLAN)

@@ -495,10 +504,11 @@

Meetups session 1/2

-
Room 1VLC media player
-
Room 2AV2 Developer Room
-
Room 3Unconferences
+
Aula AlfaVLC media player
+
Aula PorticoAV2 Developer Room
+
Aula OrianaUnconferences
+

All located on the ground floor.

@@ -506,10 +516,11 @@

Meetups session 2/2

-
Room 1TBD
-
Room 2FFmpeg
-
Room 3Unconferences
+
Aula AlfaTBD
+
Aula PorticoFFmpeg
+
Aula OrianaUnconferences
+

All located on the ground floor.

@@ -714,9 +725,9 @@

Unconferences

-
Room 1
-
Room 2
-
Room 3
+
Aula Alfa
+
Aula Portico
+
Aula Oriana
@@ -792,6 +803,7 @@

Conference

Sapienza Conference Centre, Sapienza University of Rome

Via Salaria 113, 00198 Roma, Italy

+

Meetups and unconferences will take place in Aula Alfa, Aula Portico and Aula Oriana, all located on the ground floor. You are also allowed to hangout in the outdoor courtyards!


View Larger Map
View it on GitLab: https://code.videolan.org/VideoLAN.org/websites/-/commit/5acac032b6fb914a29df646dfc6c2c4e795a1fde -- View it on GitLab: https://code.videolan.org/VideoLAN.org/websites/-/commit/5acac032b6fb914a29df646dfc6c2c4e795a1fde You're receiving this email because of your account on code.videolan.org. Manage all notifications: https://code.videolan.org/-/profile/notifications | Help: https://code.videolan.org/help