
Technical details and publication about CVE-2026-38698 and CVE-2026-38699
Heap Overflow on tutk_packet_alloc function in tutk_av_server
TUTK SDK v.3.1.10.0 through v.4.3.8.1
tutk_packet_Alloc function
An authenticated attacker must send a crafted oversized AV packet derived from a decrypted UDP payload to port 32761.
OOB Read on 0x407 Handler
TUTK SDK v.3.1.10.0 through v.4.3.8.1
__Fill_ReadBuf function
An local attacker must send a crafted UDP packet with an invalid payload offset.