NULL pointer dereference in shairport-sync - #VU147258
Published: September 7, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a null-pointer dereference in the handle_setup_2() AirPlay-2 SETUP handler when processing a SETUP plist containing a non-string timingPeerInfo.Addresses element. A remote attacker can send a specially crafted SETUP request to cause a denial of service.
AirPlay-2 transient pairing does not require a user-entered PIN by default.