> USN-8764-1: SRT vulnerabilities
[DATE: 15/09/2026 13:49]
[LANGUAGE: EN]
It was discovered that SRT did not authenticate certain encryption control
messages. A remote attacker could possibly use this issue to downgrade an
encrypted connection and inject arbitrary content or interrupt a media
stream. (CVE-2026-55868)
It was discovered that SRT did not properly validate certain control
packets during connection setup and key refresh operations. A remote
attacker could possibly use this issue to cause SRT to crash, resulting in
a denial of service. (CVE-2026-55869)