VLC flaws enable memory corruption and data leakage
Two newly disclosed vulnerabilities affecting VLC media player 3.0.0 through 3.0.23 can corrupt heap memory or expose data when users open a malicious PNG image or connect to an attacker-controlled RealRTSP server, security records published this week show. The more serious issue, CVE-2026-56711, is an integer-overflow flaw in VLC’s picture-allocation logic that can lead to a heap out-of-bounds…
Two newly discovered vulnerabilities in VLC media player versions 3.0.0 through 3.0.23 can lead to memory corruption and data leakage. The more severe of the two, CVE-2026-56711, is an integer-overflow flaw in the picture-allocation logic, which can cause heap out-of-bounds writes. This vulnerability has a high severity rating of 8.6 (v4) and 8.8 (v3.1) and can be triggered by opening a specially crafted PNG image or connecting to an attacker-controlled RealRTSP server.
The second vulnerability, CVE-2026-73324, affects VLC's RealRTSP handling and allows attackers to disclose portions of heap memory. Both vulnerabilities require user interaction and no privileges, with the first vulnerability having a higher impact on confidentiality, integrity, and availability.
Brief written by urgent.news from Arabian Post's own syndicated text. Machine-written — may contain errors; check the original before relying on it.