{"id":"CVE-2026-38998","title":"A use-after-free in the SocketDescriptor::tcpReadHandler1 function (liveMedia/RTPInterface.cpp) of LIVE555 Streaming Media (version 2026.02.26) allows attackers to cause a Denial of Service (DoS) via sending a series of crafted RTSP and …","summary":"A use-after-free in the SocketDescriptor::tcpReadHandler1 function (liveMedia/RTPInterface.cpp) of LIVE555 Streaming Media (version 2026.02.26) allows attackers to cause a Denial of Service (DoS) via sending a series of crafted RTSP and …","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","cvssSource":"adp","ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-14T12:15:15.332221Z"},"published":"2026-09-09","updated":"2026-09-14","sourceUpdated":"2026-09-14T12:15:58.063Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2026-38998","references":[{"url":"http://lists.live555.com/pipermail/live-devel/2026-March/022789.html"},{"url":"https://download.live555.com/changelog.txt"},{"url":"https://github.com/archersec/security-advisories/blob/master/live555/live555-advisory-2026.md"}],"tags":["cve.org"],"epss":0.0024,"epssPercentile":0.15443,"ingestedAt":"2026-09-14T15:23:07.432Z","slug":"CVE-2026-38998","body":"## Overview\n\nA use-after-free in the SocketDescriptor::tcpReadHandler1 function (liveMedia/RTPInterface.cpp) of LIVE555 Streaming Media (version 2026.02.26) allows attackers to cause a Denial of Service (DoS) via sending a series of crafted RTSP and HTTP requests to the server.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}