USN-8764-1: SRT vulnerabilities
Ubuntu fixes two SRT flaws allowing encrypted connection downgrade with content injection and remote crash.
Ubuntu Security Notice USN-8764-1 patches two vulnerabilities in the SRT streaming protocol. CVE-2026-55868 stems from unauthenticated encryption control messages, letting a remote attacker downgrade an encrypted connection to inject content or interrupt media streams. CVE-2026-55869 involves improper validation of control packets during connection setup and key refresh, enabling a remote denial of service.
- CVE-2026-55868: unauthenticated encryption control messages allow connection downgrade
- Downgraded connections enable arbitrary content injection or stream interruption
- CVE-2026-55869: invalid control packet handling causes crash and denial of service
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-55868 | NVD description · AI analysis pending | — | — | — | — | — | |
| CVE-2026-55869 | NVD description · AI analysis pending | — | — | — | — | — |
It was discovered that SRT did not authenticate certain encryption control messages. A remote attacker could possibly use this issue to downgrade an encrypted connection and inject arbitrary content or interrupt a media stream. (CVE-2026-55868) It was discovered that SRT did not properly validate certain control packets during connection setup and key refresh operations. A remote attacker could possibly use this issue to cause SRT to crash, resulting in a denial of service. (CVE-2026-55869)
This source does not provide full text. Read it at ubuntu.com.