CVE-2018-11529: Debian Linux

High severity, CVSS 8.0. EPSS: 37% chance of exploitation in the next 30 days.

VideoLAN VLC media player 2.2.x is prone to a use after free vulnerability which an attacker can leverage to execute arbitrary code via crafted MKV files. Failed exploit attempts will likely result in denial of service conditions.

Affected products

  • Debian Debian Linux: version 9.0 only
  • Videolan Vlc Media Player: up to and including 2.2.8

Published 2018-07-11. Last modified 2026-06-17.