ZeroHour
Ubuntu Security Noticespublished ()ingested

USN-8764-1: SRT vulnerabilities

AI summary · glm-5.3

Ubuntu fixes two SRT flaws allowing encrypted connection downgrade with content injection and remote crash.

Ubuntu Security Notice USN-8764-1 patches two vulnerabilities in the SRT streaming protocol. CVE-2026-55868 stems from unauthenticated encryption control messages, letting a remote attacker downgrade an encrypted connection to inject content or interrupt media streams. CVE-2026-55869 involves improper validation of control packets during connection setup and key refresh, enabling a remote denial of service.

  • CVE-2026-55868: unauthenticated encryption control messages allow connection downgrade
  • Downgraded connections enable arbitrary content injection or stream interruption
  • CVE-2026-55869: invalid control packet handling causes crash and denial of service

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-55868

NVD description · AI analysis pending
CVE-2026-55869

NVD description · AI analysis pending
Full article

It was discovered that SRT did not authenticate certain encryption control messages. A remote attacker could possibly use this issue to downgrade an encrypted connection and inject arbitrary content or interrupt a media stream. (CVE-2026-55868) It was discovered that SRT did not properly validate certain control packets during connection setup and key refresh operations. A remote attacker could possibly use this issue to cause SRT to crash, resulting in a denial of service. (CVE-2026-55869)

This source does not provide full text. Read it at ubuntu.com.