Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
7.3
CVE-2026-56711: VLC can crash or run code from crafted files
CVE-2026-56711 · published 1 month ago
Summary
Versions of VLC media player from 3.0.0 to 3.0.23 can be tricked by specially made video or audio files. If a user opens such a file, the program may stop working or execute unwanted code with the same rights as VLC. Update VLC to the latest version or apply the vendor's security update to protect against this.
What to do
- Update debian vlc to version 3.0.24-0+deb13u1.
- Update debian vlc to version 3.0.24-1.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | videolan | vlc media player | <= 3.0.23 |
| Ubuntu:Pro:16.04:LTS | canonical | vlc | All versions |
| Debian:12 | debian | vlc | All versions |
| Debian:13 | debian | vlc |
< 3.0.24-0+deb13u1 Fix: upgrade to 3.0.24-0+deb13u1
|
| Debian:14 | debian | vlc |
< 3.0.24-1 Fix: upgrade to 3.0.24-1
|
Original advisory text
VLC media player 3.0.0 through 3.0.23 memory corruption vulnerability
VLC media player versions 3.0.0 through 3.0.23 contain a memory-safety vulnerability reachable when processing crafted media. Exploitation requires user interaction and may result in application termination or code execution with the privileges of the VLC process.
References
- https://github.com/videolan/vlc/blob/3.0.23/include/vlc_picture.h URL
- https://github.com/videolan/vlc/blob/3.0.23/src/misc/picture.c URL
- https://github.com/videolan/vlc/blob/3.0.23/modules/codec/png.c URL
- https://github.com/videolan/vlc/blob/3.0.23/modules/demux/image.c URL
- https://www.vulncheck.com/advisories/vlc-media-player-3.0.0-through-3.0.23-heap-... Vendor Advisory
- https://ubuntu.com/security/CVE-2026-56711 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-56711 Third Party Advisory
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/56xxx/CVE-2026-56711... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-56711 Vendor Advisory
- https://github.com/videolan/vlc
- https://security-tracker.debian.org/tracker/CVE-2026-56711 Vendor Advisory
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Severity
7.3
High
Type
CWE-190Integer Overflow
CWE-787Out-of-bounds Write
Timeline
Published9 Sep 2026
Updated9 Oct 2026
First seen9 Sep 2026
Sources
CVE-2026-56711 · NVD
CVE-2026-56711 · MITRE
UBUNTU-CVE-2026-56711 · OSV
CVE-2026-56711 · OSV
DEBIAN-CVE-2026-56711 · OSV
Track software like this
Free during beta