Description
Certain VLC media player builds in versions 3.0.0 through 3.0.23 contain a memory-safety vulnerability reachable when processing media from an attacker-controlled network source. Exploitation requires user interaction and may disclose a limited, layout-dependent amount of VLC process memory. Exposure depends on build configuration.
Published: 2026-09-09
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Data Exposure
Action: Patch
AI Analysis

Impact

Certain VLC media player builds in versions 3.0.0 through 3.0.23 contain a memory‑safety vulnerability that can be reached when processing media from an attacker‑controlled network source. The flaw, which involves a buffer overrun (CWE‑125) and an improper conversion (CWE‑170), may disclose a limited, layout‑dependent portion of the VLC process memory. Exploitation requires user interaction, such as opening a malicious media file or stream.

Affected Systems

VideoLAN VLC media player versions 3.0.0 through 3.0.23 are affected. The vulnerability is present in builds that include network source handling, such as those compiled with the RTSP module enabled. Exposure depends on the build configuration and is confined to the process memory of the player.

Risk and Exploitability

The CVSS base score is 5.3, reflecting medium severity, while the EPSS score indicates a very low but non‑zero likelihood of exploitation (<1 %). The vulnerability is not listed in CISA’s KEV catalog. Because the exploitation path requires user interaction and an attacker‑controlled network source, the risk is primarily tied to untrusted media being opened by the client.

Generated by OpenCVE AI on September 21, 2026 at 05:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update VLC media player to release 3.0.24 or later where the buffer handling bug is fixed
  • If an update is not feasible, avoid or disable remote network source modules such as RTSP in VLC
  • Restrict network connections to trusted IP ranges to reduce the chance of malicious media being delivered

Generated by OpenCVE AI on September 21, 2026 at 05:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6515-1 vlc security update
References
History

Mon, 14 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 11:30:00 +0000


Mon, 14 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
Description VLC media player copies an RTSP response line into a fixed buffer without guaranteeing termination and then treats that buffer as a C string. RtspReadLine in modules/access/rtsp/access.c calls strncpy with the full buffer length, which writes no terminator when the source line is at least as long as the destination, and rtsp_get in modules/access/rtsp/rtsp.c allocates that buffer as BUF_SIZE bytes and passes it to strdup. When a server returns a line of 4096 bytes or more, strdup measures its length past the end of the allocation and copies adjacent heap bytes until an incidental zero byte. Because the affected line is the Session header, the disclosed bytes are retained as the session identifier and sent back to the server on every subsequent request, so the operator of a hostile server reads heap memory from the client rather than inferring it. The attacker controls the line length and therefore how far the read runs. A single playlist entry naming a realrtsp URL is sufficient. The module is a build-time option, disabled in some distribution packages and enabled in the official VideoLAN builds. Certain VLC media player builds in versions 3.0.0 through 3.0.23 contain a memory-safety vulnerability reachable when processing media from an attacker-controlled network source. Exploitation requires user interaction and may disclose a limited, layout-dependent amount of VLC process memory. Exposure depends on build configuration.
Title VLC media player 3.0.0 through 3.0.23 Heap Out-of-Bounds Read via Unterminated RealRTSP Response Line VLC media player 3.0.0 through 3.0.23 information disclosure vulnerability
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Wed, 09 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Description VLC media player copies an RTSP response line into a fixed buffer without guaranteeing termination and then treats that buffer as a C string. RtspReadLine in modules/access/rtsp/access.c calls strncpy with the full buffer length, which writes no terminator when the source line is at least as long as the destination, and rtsp_get in modules/access/rtsp/rtsp.c allocates that buffer as BUF_SIZE bytes and passes it to strdup. When a server returns a line of 4096 bytes or more, strdup measures its length past the end of the allocation and copies adjacent heap bytes until an incidental zero byte. Because the affected line is the Session header, the disclosed bytes are retained as the session identifier and sent back to the server on every subsequent request, so the operator of a hostile server reads heap memory from the client rather than inferring it. The attacker controls the line length and therefore how far the read runs. A single playlist entry naming a realrtsp URL is sufficient. The module is a build-time option, disabled in some distribution packages and enabled in the official VideoLAN builds.
Title VLC media player 3.0.0 through 3.0.23 Heap Out-of-Bounds Read via Unterminated RealRTSP Response Line
First Time appeared Videolan
Videolan vlc Media Player
Weaknesses CWE-125
CWE-170
CPEs cpe:2.3:a:videolan:vlc_media_player:*:*:*:*:*:*:*:*
Vendors & Products Videolan
Videolan vlc Media Player
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Videolan Vlc Media Player
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-14T13:17:11.696Z

Reserved: 2026-08-11T21:47:14.059Z

Link: CVE-2026-73324

cve-icon Vulnrichment

Updated: 2026-09-14T13:17:07.087Z

cve-icon NVD

Status : Deferred

Published: 2026-09-09T14:17:13.347

Modified: 2026-09-14T14:17:08.940

Link: CVE-2026-73324

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T05:45:10Z

Weaknesses