Impact
The vulnerability is a memory‑safety flaw that can be triggered by processing crafted media files. Based on the description, it is inferred that the attack vector requires the user to open a malicious media file, meaning exploitation requires user interaction. The flaw allows the attacker to either cause the VLC process to terminate or execute code with the privileges of that process.
Affected Systems
All versions of VideoLAN VLC media player from 3.0.0 up to and including 3.0.23 are affected. No sub‑version specific patches are listed; the vulnerability resides in the core picture allocation routines shared across these releases.
Risk and Exploitability
The CVSS score of 7.3 indicates a moderate‑to‑high severity vulnerability. EPSS data remains low, at < 1%, suggesting a very low likelihood of widespread exploitation in the near term. The flaw is not catalogued in the CISA KEV list. The attack requires a malicious media file to be opened by the user; the attack vector is therefore user‑directed, and exploitation is classified as user‑initiated. If exploited, the attacker may cause the VLC process to terminate or execute code with the process's privileges, potentially compromising the host system.
OpenCVE Enrichment
Debian DSA