openwrt ▾
›
master ▾
›
vulnerability
›
CVE-2025-63648
Component Overview
Vulnerability Overview
Name
CVE-2025-63648
Source
NVD (
link
)
Debian (
link
)
Description
A NULL pointer dereference in the dacp_reply_playqueueedit_move function (src/httpd_dacp.c) of owntone-server commit b7e385f allows attackers to cause a Denial of Service (DoS) via sending a crafted DACP request to the server.
CWEs
CWE-476
Published Date
Jan 20, 2026
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://github.com/archersec/security-advisories/blob/master/owntone-server/owntone-server-advisory-2025.md
Patch
https://github.com/owntone/owntone-server/commit/5f526c7a7e08c567a5c72421d74a79dafdd07621
Patch
https://github.com/owntone/owntone-server/issues/1933
Issue Tracking
Analysis
#
Affected Component
Analysis
owntone
Exploitable
Vulnerability Ratings
#
7.5
CVSSv31
NaN
other