GHSA-6xg9-784j-24rm
CVE Information
Impact
A heap-based buffer overflow exists in the SRT protocol library when processing KMREQ control packets during connection setup and key refresh operations. A remote attacker can send a specially crafted packet that causes the SRT process to crash. No valid credentials, passphrase, or completed handshake are required.
This vulnerability affects all SRT endpoints — senders and receivers — in any connection mode (listener, caller, rendezvous). Endpoints in listener mode are directly exploitable by any attacker who can reach the listening port. Endpoints in any mode are exploitable if the attacker can observe session traffic and identify the 5-tuple (source IP, source port, destination IP, destination port, SRT socket ID). Endpoints restricted to known source IPs via security groups or firewalls are protected by their network architecture. Standard network security practices (VPN, private connectivity, network segmentation) significantly reduce the attack surface.
Patches
https://github.com/Haivision/srt/releases/tag/v1.5.6 https://github.com/Haivision/srt/pull/3345
Workarounds
None at this time.
References
https://www.haivision.com/product-bulletin-srt-security-advisory/ https://srtalliance.org/srt-alliance-security-advisory/