yocto ▾
›
kirkstone ▾
›
vulnerability
›
CVE-2025-51602
Component Overview
Vulnerability Overview
Name
CVE-2025-51602
Source
NVD (
link
)
Debian (
link
)
Description
mmstu.c in VideoLAN VLC media player before 3.0.22 allows an out-of-bounds read and denial of service via a crafted 0x01 response from an MMS server.
CWEs
CWE-125
Published Date
Jan 16, 2026
Updated Date
Jun 17, 2026
Workaround
-
Advisories
Analysis
#
Affected Component
Analysis
vlc
Exploitable
Vulnerability Ratings
#
4.8
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
vlc
buildroot
2025.02.x
3.0.23
Not Affected
vlc
buildroot
master
3.0.23
Not Affected
vlc
yocto
master
3.0.23
Not Affected
vlc
yocto
scarthgap
3.0.20
Exploitable