Description
RAOP module accepts unbounded Content-Length values and does not check the pw_array_add() return.
Published: 2026-07-01
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The RAOP module in PipeWire mistakenly allows the Content-Length header to be unbounded, and it fails to verify the result of pw_array_add(). If an attacker sends a request with a very large Content-Length value, the module can dereference a null pointer, causing the PipeWire daemon to crash. This flaw is a classic NULL pointer dereference, classified as CWE-476, which results in a denial of service that can affect all users on the affected system.

Affected Systems

Red Hat Red Enterprise Linux 8, 9, 10 that run PipeWire with the RAOP modules module-raop-discover and module-raop-sink are impacted.

Risk and Exploitability

The CVSS base score of 6.5 indicates moderate severity, while the EPSS less than 1% signals a very low probability of real‑world exploitation, and the CVE is not listed in CISA KEV. Based on the description, it is inferred that the attack vector involves an attacker sending an oversized RTSP/RAOP request over the network RTSP port, which could trigger the null pointer dereference.

Generated by OpenCVE AI on July 21, 2026 at 14:26 UTC.

Remediation

Vendor Workaround

If AirPlay streaming is not required, unload or disable the module-raop-discover and module-raop-sink PipeWire modules.


OpenCVE Recommended Actions

  • Unload or disable PipeWire modules module-raop-discover and module-raop-sink.
  • Apply the latest PipeWire update or Red Hat patch when available to address the null pointer dereference.
  • Restrict network access to RTSP/RAOP ports or disable AirPlay services until a fix is applied.

Generated by OpenCVE AI on July 21, 2026 at 14:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Ubuntu USN Ubuntu USN USN-8535-1 PipeWire vulnerabilities
History

Thu, 02 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Wed, 01 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Description RAOP module accepts unbounded Content-Length values and does not check the pw_array_add() return.
Title Pipewire: raop rtsp null deref
First Time appeared Redhat
Redhat enterprise Linux
Weaknesses CWE-476
CPEs cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Redhat Enterprise Linux
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-07-22T13:56:24.714Z

Reserved: 2026-07-01T12:14:59.165Z

Link: CVE-2026-14324

cve-icon Vulnrichment

Updated: 2026-07-01T16:15:26.350Z

cve-icon NVD

No data.

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-07-01T00:00:00Z

Links: CVE-2026-14324 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T14:30:08Z

Weaknesses