NULL pointer dereference in the dacpreplyplayqueueeditclear function in src/httpddacp.c in owntone-server through commit 6d604a1 (newer commit after version 28.12) allows remote attackers to cause a Denial of Service (crash).
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-57156.json"
[
{
"id": "CVE-2025-57156-b6f85b3e",
"signature_type": "Function",
"digest": {
"function_hash": "265906059652663118601435356401398868101",
"length": 432.0
},
"target": {
"file": "src/httpd_dacp.c",
"function": "dacp_reply_playqueueedit_clear"
},
"source": "https://github.com/owntone/owntone-server/commit/5e4d40ee03ae22ab79534bb1410fa9db96c9fabd",
"signature_version": "v1",
"deprecated": false
},
{
"id": "CVE-2025-57156-f7845b15",
"signature_type": "Line",
"digest": {
"line_hashes": [
"158674466965424907838216926545958290299",
"11845804404603833354839626176267856447",
"194268673386357485042971034960685202820",
"75317284670289669780758649940199479625",
"23440141608120423264337129654445761972",
"234291141180925024453902219501435956715"
],
"threshold": 0.9
},
"target": {
"file": "src/httpd_dacp.c"
},
"source": "https://github.com/owntone/owntone-server/commit/5e4d40ee03ae22ab79534bb1410fa9db96c9fabd",
"signature_version": "v1",
"deprecated": false
}
]