security advisorycriticalremote attack
It was discovered that there was a origin-validation error in rtpengine, an open-source media proxy for real-time audio and video traffic. CVE-2025-53399 The endpoint-learning logic of the media-relay core could have. Debian LTS Advisory DLA-4691-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Chris Lamb July 20, 2026 https://wiki.debian.org/LTS Package : rtpengine Version : 10.5.3.5-1+deb12u1 CVE ID : CVE-2025-53399 Debian Bug : 1110316 It was discovered that there was a origin-validation error in rtpengine, an open-source media proxy for real-time audio and video traffic. CVE-2025-53399 The endpoint-learning logic of the media-relay core could have allowed an remote attacker to inject or intercept media streams via malicious RTP packets. For Debian 12 bookworm, this problem has been fixed in version 10.5.3.5-1+deb12u1. We recommend that you upgrade your rtpengine packages. For the detailed security status of rtpengine please refer to its security tracker page at: https://security-tracker.debian.org/tracker/rtpengine Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . A critical security update for rtpengine on Debian LTS addresses an origin-validation error allowing remote attacks via RTP.. rtpengine update, media proxy security, Debian LTS, remote attack fix, origin-validation error. . Severity: Critical. LinuxSecurity.com Team
Jul 21, 2026
•Critical
Debian LTS