CVE-2025-60458Patch(antimof / uxplay)

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch antimof uxplay systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

UxPlay 1.72 contains a double free vulnerability in its RTSP request handling. A specially crafted RTSP TEARDOWN request can trigger multiple calls to free() on the same memory address, potentially causing a Denial of Service.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-400

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • uxplay

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
uxplay

1 version affected across 1 product

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-03-21: 1Patch / Workaround · 2026-03-21: 1Technical Details · 2026-03-21: 103-21
Signal classification1 categories
Patch
1100.0%
Referenced assets1 URL
Full discourse1 post
  • ThreatCluster@threatcluster
    Patch

    Fedora 42 and 43 ship uxplay 1.73.3 updates fixing CVE-2025-60458, a double-free in RTSP TEARDOWN that can trigger DoS in AirPlay2 Mirror/Audio servers. Users should update via dnf. https://threatcluster.io/cluster/fedora-42-and-43-uxplay-1733-vulnerabilities-addressed-01a8eb32

    Post summary

    Fedora 42 and 43 users are advised to update uxplay to version 1.73.3 via dnf to patch CVE-2025-60458, a double‑free that could cause DoS in AirPlay2 Mirror/Audio servers.

    00000141
    105 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appantimofuxplay1.72--

Explore more