Stack-based buffer overflow in shairport-sync - #VU147255
Published: September 7, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a stack-based buffer overflow in the RTSP conversation thread in rtsp.c when hex-dumping the body of an RTSP request with an unrecognised method. A remote attacker can send an RTSP request with an unrecognised method and a large body to cause a denial of service.
On AirPlay 2 receivers, the issue is reachable before RTSP authentication.