[www-doc] [Git][VideoLAN.org/websites][master] Add VLC 3.0.24 Security Bulletin

Thomas Guillem (@tguillem) gitlab at videolan.org
Thu Oct 1 12:10:17 UTC 2026



Thomas Guillem pushed to branch master at VideoLAN organization / websites


Commits:
d7b11940 by Thomas Guillem at 2026-10-01T14:08:25+02:00
Add VLC 3.0.24 Security Bulletin

- - - - -


2 changed files:

- www.videolan.org/security/index.php
- + www.videolan.org/security/sb-vlc3024.php


Changes:

=====================================
www.videolan.org/security/index.php
=====================================
@@ -19,6 +19,13 @@
     <div class="col-md-6">
         <h2>VLC releases Security Bulletins <em>(SB)</em></h2>
            <p>Those bulletins are related to each VLC release and can be made of multiple security issues, internal and external.</p>
+           <h3>2026</h3>
+           <dl>
+           <dt>VideoLAN-SB-VLC-324</dt>
+           <dd>Multiple vulnerabilities fixed in VLC media player 3.0.24
+            <a href="sb-vlc3024.html">Details</a>
+           </dd>
+           </dl>
            <h3>2025</h3>
            <dl>
            <dt>VideoLAN-SB-VLC-322</dt>


=====================================
www.videolan.org/security/sb-vlc3024.php
=====================================
@@ -0,0 +1,103 @@
+<?php
+   $title = "VideoLAN Security Bulletin VLC 3.0.24";
+   $lang = "en";
+   $menu = array( "vlc" );
+   $body_color = "red";
+   require($_SERVER["DOCUMENT_ROOT"]."/include/header.php");
+?>
+
+
+<div id="fullwidth">
+
+<h1>Security Bulletin VLC 3.0.24</h1>
+
+<pre>
+Summary           : Multiple vulnerabilities addressed in VLC media player 3.0.24
+Date              : September 2026
+Affected versions : VLC media player 3.0.23 and earlier
+ID                : VideoLAN-SB-VLC-3024
+CVE references    : CVE-2026-56711, CVE-2026-73324
+</pre>
+
+<h2>Details</h2>
+<p>
+    VLC 3.0.24 fixes over 50 security issues in VLC itself. It also updates many bundled libraries, including FFmpeg, GnuTLS, libxml2 and libpng;
+    these updates include fixes for at least 74 publicly documented vulnerabilities.
+</p>
+
+<p>Higher-impact issues:</p>
+<ul>
+    <li>Heap buffer overflows in the TagLib metadata adapter when reading crafted media. (#30094)</li>
+    <li>Integer overflows in picture allocation, leading to heap buffer overflows when processing images or subtitles. (#29692)</li>
+    <li>A heap buffer overflow in WiDi LPCM audio decoding. (#29663)</li>
+    <li>Out-of-bounds reads and writes when processing ARIB logo data in MPEG transport streams. (#29957)</li>
+    <li>An integer overflow leading to a heap buffer overflow when reading metadata from a crafted VDR recording. (#29806)</li>
+    <li>A path traversal when extracting a crafted skin archive, and a heap buffer overflow when loading a crafted skin.</li>
+    <li>Disclosure of process memory to a SAT>IP server during session teardown. (#30072)</li>
+    <li>Memory-safety issues in the legacy RealRTSP plugin, addressed by disabling the plugin in packaged builds. (#29956)</li>
+</ul>
+
+<p>Additional fixes addressed:</p>
+<ul>
+    <li>Buffer overflows and invalid memory accesses in Speex, ADPCM, G.711 and AAC decoding, and in FFmpeg audio channel handling.</li>
+    <li>Invalid memory accesses in CEA-608 and CEA-708 captions, and DVD and CVD subtitles.</li>
+    <li>Out-of-bounds accesses, a use-after-free and malformed-input handling in Matroska, Ogg, AVI, MP4, MPEG-TS, TiVo TY and image demuxers, and in MMS, Smooth Streaming and RIST handling.</li>
+    <li>Disclosure of uninitialised memory in ASF and MPEG-TS stream output and raw-video RTP packets.</li>
+    <li>Invalid memory accesses in CD-ROM and CUE sheet handling, and allocation overflows in OMX IL and JPEG/PNG encoding.</li>
+    <li>FTP command injection through crafted URLs. (#30078)</li>
+</ul>
+
+<h2>Impact</h2>
+<p>These issues may cause crashes and memory disclosure with the user's privileges. Code execution has been demonstrated on macOS under specific conditions.</p>
+
+<h2>Threat mitigation</h2>
+<p>
+    Crafted files or streams can trigger these issues during opening, metadata preparsing, or playlist processing.
+    Network and stream-output issues require the affected features to be in use.
+</p>
+
+<h2>Workarounds</h2>
+<p>Users who cannot upgrade yet should refrain from opening files or streams from untrusted sources.</p>
+
+<h2>Solution</h2>
+<p>Upgrade to VLC media player <b>3.0.24</b>.</p>
+<p>Distributors should apply the bundled-library updates or equivalent patches and keep RealRTSP disabled.</p>
+
+<h2>Support</h2>
+<p>VideoLAN thanks the <a href="https://www.sovereign.tech/">Sovereign Tech Agency</a>, and especially its Sovereign Tech Fund program, for supporting VLC's sustainability and safety.</p>
+
+<h2>Credits</h2>
+<ul>
+    <li>Thomas Guillem for finding issues in audio decoding, subtitles, demuxers, network input and stream output. (#29663, #29671, #29681, #29692, #29694, #29696, #29710, #29711, #30060, #30083, #30084, #30086)</li>
+    <li>Fabian Wahle (Hap Security) for the SAT>IP disclosure and additional image-processing, RealRTSP and skin findings. (#30072, #29692, #29956, #29929; CVE-2026-56711, CVE-2026-73324)</li>
+    <li>tedanvosin for the TagLib adapter report and additional ARIB logo impact analysis. (#30094, #29957)</li>
+    <li>Kai Martin (KG3N Dynamics) for the ARIB logo and RealRTSP reports. (#29957, #29956)</li>
+    <li>Khoka Moni for the VDR report. (#29806)</li>
+    <li>François Cartegnie for the Speex, CVD subtitle and CD-ROM findings. (#30103, #29864, #29863, #29862, #29859, #29858, #29857, #29856)</li>
+    <li>tianshuo han for the TiVo TY, Matroska DVD menu, Ogg header handling and CEA-708 reports. (#29773, #29772, #29751, #29750)</li>
+    <li>HE WEI (ギカク) for the AVI subtitle, IMA/QuickTime ADPCM and G.711 reports. (#29972, #29971, #29969)</li>
+    <li>Asif Nadaf for the Ogg Annodex, DVD SPU and TiVo TY reports. (#30045, #30046, #30044)</li>
+    <li>Tristan Madani for the Ogg Skeleton and TiVo TY reports. (#29959, #29958)</li>
+    <li>Brinly for the JPEG/PNG encoding and OMX IL reports. (#29720, #29719)</li>
+    <li>Keno Hassler for the AAC channel-count report. (#30073)</li>
+    <li>oxsignal for the MP4 CEA-608 report. (#29884)</li>
+    <li>Alexandru Hossu for the Smooth Streaming report. (#29801)</li>
+    <li>Aryan Chehreghani for the MMS report. (#29987)</li>
+    <li>Trail of Bits for the cryptographic dependency report. (#29760)</li>
+    <li>Cisco Talos for reporting the outdated FFmpeg dependency. (#29732)</li>
+    <li>Mohammadmobinjavan (Ma3terPwner) and Adel Piri for the FTP command-injection report. (#30078)</li>
+    <li>The upstream library maintainers and the VideoLAN contributors for their testing, reports and fixes.</li>
+    <li>OSS-Fuzz for continuous fuzzing and issue reports throughout the release cycle. (#30080, #30037, #30024, #29954, #29895, #29893, #29887, #29879, #29852, #29837, #29835, #29834, #29832, #29831, #29822, #29808, #29807, #29800, #29781, #29776, #29756, #29728, #29686, #29677, #29670, #29657, #29636, #29634, #29578, #29565, #29561, #29560, #29546, #29541, #29521, #29518, #29517, #29449, #29446, #29444, #29321, #29289, #29227, #29223, #29057, #29001, #28991)</li>
+</ul>
+
+<h2>References</h2>
+<dl>
+    <dt>The VideoLAN project</dt>
+    <dd><a href="//www.videolan.org/">https://www.videolan.org/</a></dd>
+    <dt>VLC official Git repository</dt>
+    <dd><a href="https://code.videolan.org/videolan/vlc.git">https://code.videolan.org/videolan/vlc.git</a></dd>
+</dl>
+
+</div>
+
+<?php footer('$Id$'); ?>



View it on GitLab: https://code.videolan.org/VideoLAN.org/websites/-/commit/d7b119405b1db751ae1860057ed2a4c30d7ff638

-- 
View it on GitLab: https://code.videolan.org/VideoLAN.org/websites/-/commit/d7b119405b1db751ae1860057ed2a4c30d7ff638
You're receiving this email because of your account on code.videolan.org. Manage all notifications: https://code.videolan.org/-/profile/notifications | Help: https://code.videolan.org/help




More information about the www-doc mailing list