{"id":"openSUSE-SU-2026:21863-1","summary":"Security update for live555","details":"This update for live555 fixes the following issues:\n\nChanges in live555:\n\n- Update to version 2026.08.25:\n  * Fixed a bug in \"VorbisAudioRTPSource\" that could have caused a\n    malicious SDP description to crash a RTP client.\n\n- update to 2026.08.14:\n  * Fixed a bug that could cause a problem with subclassed variants\n    of H.264 or H.265 RTP sinks.\n  * Fixed old code in \"GroupsockHelper.cpp\" that was using\n    hardcoded numeric error numbers\n  * Fixed a memory leak that could occur when parsing a SDP\n    description that contains two or more\n  * When adding protection against the use of 'stolen' RTSP session\n    ids we forgot to do so for every \"SETUP\" command.  This release\n    fixes that.\n  * Fixed a typo in \"RTSPCommon.cpp\": \"smtpe\" -\u003e \"smpte\".\n  * Updated the RTSP server implementation to return a \"Unsupported\n    Transport\" error if a \"SETUP\" request does not include a\n    \"Transport:\" header.\n  * Added \"-std=c++20\" to the \"CPLUSPLUS_FLAGS\" line in each\n    \"config.*\" file, so that \"std::atomic_flag::test\" will compile\n    with compilers that support\n  * Made the parsing of MP3 audio files more robust to protect\n    against malformed MP3 data.\n  * Minor change to \"testProgs/testRTSPClient.cpp\" to make\n    compiling on Mac OS X happier.\n\n- Update to version 2026.06.01:\n  * Updated the \"RTSPServer\" implementation of the \"SETUP\" command\n    to make it more robust if subclassed code reimplements\n    \"lookupServerMediaSession()\" as an asynchronous operation.\n\n- update to 2026.05.30:\n  * Updated the \"RTSPServer\" implementation some more to make it\n    more robust if subclassed code reimplements\n    \"lookpServerMediaSession()\" as an asynchronous operation.\n  * Added an (integer) index to identify each server's\n    'client connection', and changed the \"fClientConnections\" table\n    to be indexed by this id.\n  * In the \"RTSPServer\" implementation, removed the\n    \"fOurClientConnection\" member variable.\n    This had been left over from when the RTSP \"SETUP\" command had\n    been implemented as a single, synchronous function.\n    Now that \"SETUP\" is implemented using multiple functions,\n    possibly asynchronously (depending upon how\n    \"lookpServerMediaSession()\" is implemented), this member\n    variable was potentially dangerous if more than one \"SETUP\" is\n    performed concurrently on the same client connection, or on\n    separate client connections.\n\n- update to 2026.05.28:\n  * fix use-after-free memory corruption introduced in fix\n    for CVE-2026-41470\n\n- Update to version 2026.04.22 (CVE-2026-41470, boo#1265856):\n  * Added extra checking to the handling of the RTSP server's\n    \"PLAY\", \"PAUSE\", \"TEARDOWN\", and \"SET_PARAMETER\" commands, to\n    ensure that, if the session is authenticated, then a proper\n    authentication check is done before these commands are handled.\n    This protects against the use of a 'stolen' RTSP session id to\n    send these commands.  (Note, however, that if the session is\n    not authenticated (i.e., no username,password is needed), then no\n    such protection is possible.)\n- Changes from version 2026-04-01:\n  * Updated the way that the RTSP server generates successive RTSP\n    'session ids' to make it less likely that an attacker could\n    guess a session id.\n  * Updated the RTSP server implementation to make it possible for\n    a client to request both interleaved (i.e., RTP/RTCP-over-TCP)\n    and non-interleaved (i.e., RTP/RTCP-over-UDP) delivery within\n    the same session.\n\n- Update to version 2026.03.23 (boo#1279932):\n  * CVE-2026-38998: Fixed a bug in the RTSP server code that caused\n    it to improperly handle non-interleaved \"SETUP\"s that were sent\n    for a session where interleaving (i.e., RTP/RTCP-over-TCP) had\n    already been \"SETUP\".  (This could cause a 'use-after-free'\n    error.\n  * For changes between 2024.08.01 to today, please refer to\n    https://download.live555.com/changelog.txt\n\n- update to 2024-08-01:\n  * Updated \"ServerMediaSession::generateSDPDescription()\" to\n    treat \"time_t\" as (long long).\n","modified":"2026-09-17T18:23:14.637807206Z","published":"2026-09-16T15:16:27Z","related":["CVE-2026-38998","CVE-2026-41470"],"upstream":["CVE-2026-38998","CVE-2026-41470"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265856"},{"type":"REPORT","url":"https://bugzilla.suse.com/1279932"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-38998"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-41470"}],"affected":[{"package":{"name":"live555","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/live555&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2026.08.25-bp160.1.1"}]}],"ecosystem_specific":{"binaries":[{"live555":"2026.08.25-bp160.1.1","live555-devel":"2026.08.25-bp160.1.1","libBasicUsageEnvironment2":"2026.08.25-bp160.1.1","libUsageEnvironment3":"2026.08.25-bp160.1.1","libgroupsock33":"2026.08.25-bp160.1.1","libliveMedia120":"2026.08.25-bp160.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21863-1.json"}}],"schema_version":"1.9.0"}