CVE-2026-38998
Awaiting Analysis Awaiting Analysis - Queue

Use-After-Free in LIVE555 Streaming Media

Vulnerability report for CVE-2026-38998, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-14

Assigner: MITRE

Description

A use-after-free in the SocketDescriptor::tcpReadHandler1 function (liveMedia/RTPInterface.cpp) of LIVE555 Streaming Media (version 2026.02.26) allows attackers to cause a Denial of Service (DoS) via sending a series of crafted RTSP and HTTP requests to the server.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-14
Generated
2026-09-30
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
live555 streaming_media 2026.03.23
live555 streaming_media 2026.02.26

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-416 The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-38998 is a use-after-free vulnerability in LIVE555 Streaming Media version 2026.02.26. It occurs in the SocketDescriptor::tcpReadHandler1 function where a memory buffer is freed but later accessed again. Attackers exploit this by sending crafted RTSP and HTTP requests to trigger a Denial of Service (DoS) on the server.

Detection Guidance

Monitor for crashes or hangs in LIVE555-based RTSP servers after receiving RTSP or HTTP requests. Check logs for segmentation faults in the liveMedia/RTPInterface.cpp module. Use network traffic analysis tools like Wireshark to inspect for malformed RTSP/HTTP packets targeting the tcpReadHandler1 function.

Impact Analysis

This vulnerability allows attackers to crash the LIVE555 server by sending malicious requests, causing service disruption. If you run a server using LIVE555 version 2026.02.26, your system may become unresponsive or restart unexpectedly due to the DoS attack.

Compliance Impact

This vulnerability primarily causes Denial of Service (DoS) conditions through crafted RTSP and HTTP requests, which may disrupt service availability. While not directly violating GDPR or HIPAA, prolonged DoS conditions could impact data processing operations subject to these regulations, potentially leading to non-compliance due to interrupted access to personal or health data.

Mitigation Strategies

Upgrade LIVE555 to version 2026.03.23 or later to apply the security fixes. If upgrading is not immediately possible, restrict network access to the RTSP server using firewalls or disable RTSP/HTTP interfaces until patched. Monitor for unusual traffic patterns that may indicate exploitation attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-38998. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart