Bug 2543600 (CVE-2026-102875)

Summary: CVE-2026-102875 vlc: vlc: arbitrary code execution via path traversal in skin archives
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedKeywords: Security
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in VLC media player. An attacker can achieve arbitrary code execution by convincing a user to open a maliciously crafted skin archive. Because the theme loader fails to properly validate member file paths within the archive, files containing directory traversal sequences can be written to arbitrary locations with the privileges of the running application.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2543798, 2543799    
Bug Blocks:    

Description OSIDB Bzimport 2026-09-29 20:18:26 UTC
VLC media player before 3.0.24 contains a path traversal vulnerability in the skins2 ThemeLoader that fails to validate member names in .vlt skin archives. Attackers can craft malicious skin files with path traversal sequences to write arbitrary files with VLC user privileges, enabling code execution through Lua script injection.