---
id: CVE-2026-38998
title: >-
  A use-after-free in the SocketDescriptor::tcpReadHandler1 function
  (liveMedia/RTPInterface.cpp) of LIVE555 Streaming Media (version 2026.02.26)
  allows attackers to cause a Denial of Service (DoS) via sending a series of
  crafted RTSP and …
summary: >-
  A use-after-free in the SocketDescriptor::tcpReadHandler1 function
  (liveMedia/RTPInterface.cpp) of LIVE555 Streaming Media (version 2026.02.26)
  allows attackers to cause a Denial of Service (DoS) via sending a series of
  crafted RTSP and …
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'
cvssSource: adp
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-14T12:15:15.332221Z'
published: '2026-09-09'
updated: '2026-09-14'
sourceUpdated: '2026-09-14T12:15:58.063Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2026-38998'
references:
  - url: 'http://lists.live555.com/pipermail/live-devel/2026-March/022789.html'
  - url: 'https://download.live555.com/changelog.txt'
  - url: >-
      https://github.com/archersec/security-advisories/blob/master/live555/live555-advisory-2026.md
tags:
  - cve.org
epss: 0.00439
epssPercentile: 0.35562
ingestedAt: '2026-09-14T15:23:07.432Z'
---

## Overview

A use-after-free in the SocketDescriptor::tcpReadHandler1 function (liveMedia/RTPInterface.cpp) of LIVE555 Streaming Media (version 2026.02.26) allows attackers to cause a Denial of Service (DoS) via sending a series of crafted RTSP and HTTP requests to the server.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
