# Buffer overflows in Plex Commercial Skipper

**URL:** <https://forums.plex.tv/t/buffer-overflows-in-plex-commercial-skipper/935638>\
**Category:** Plex Media Server\
**Tags:** livetv-dvr, server-windows, server-mac, server-linux, server-nvidia-shield, server-docker, server-qnap, server-synology, server-truenas\
**Created:** [January 21, 2026, 6:34am UTC](https://forums.plex.tv/t/buffer-overflows-in-plex-commercial-skipper/935638 "2026-01-21T06:34:25Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![Gloppie](https://avatars.discourse-cdn.com/v4/letter/g/74df32/32.png) [@Gloppie](https://forums.plex.tv/u/Gloppie)\
**Post date:** [January 21, 2026, 6:34am UTC](https://forums.plex.tv/t/buffer-overflows-in-plex-commercial-skipper/935638/1 "2026-01-21T06:34:25Z")

</div>

Server Version#: ALL  
I tried to reach out to your bug bounty, but you ignored me.

```auto
>>> Source unpacked in /var/tmp/portage/media-tv/Comskip-0_p20250418/work
>>> Preparing source in /var/tmp/portage/media-tv/Comskip-0_p20250418/work/Comskip-0_p20250418 ...
>>> Source prepared.
>>> Configuring source in /var/tmp/portage/media-tv/Comskip-0_p20250418/work/Comskip-0_p20250418 ...
Preparing the Comskip build system...please wait

<snip>
]comskip.c: In function ‘OpenOutputFiles’:
comskip.c:6518:39: warning: �-Wformat-overflow=e[me[K][]]
 6518 | sprintf(tempstr, "%s%c%s", cwd, PATH_SEPARATOR, inbasename);
      | ^~ ~~~~~~~~~~
In function ‘sprintf’,
    inlined from ‘OpenOutputFiles’ at comskip.c:6518:17:
/usr/include/bits/stdio2.h:30:10: note: ‘ __builtin___ sprintf_chk’ output between 2 and 512 bytes into a destination of size 256
   30 | return __builtin___ sprintf_chk ( __s,__ USE_FORTIFY_LEVEL - 1,
      | ^ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   31 | __glibc_objsize (__s), __fmt,
      | ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   32 | __va_arg_pack ());
      | ~~~~~~~~~~~~~~~~~
comskip.c: In function ‘OpenOutputFiles’:
comskip.c:6532:30: warning: �-Wformat-overflow=e[me[K][]]
 6532 | sprintf(filename, "%s.Xcl", mpegfilename);
      | ^~~~
In function ‘sprintf’,
    inlined from ‘OpenOutputFiles’ at comskip.c:6532:9:
/usr/include/bits/stdio2.h:30:10: note: ‘ __builtin___ sprintf_chk’ output between 5 and 260 bytes into a destination of size 256
   30 | return __builtin___ sprintf_chk ( __s,__ USE_FORTIFY_LEVEL - 1,
      | ^ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   31 | __glibc_objsize (__s), __fmt,
      | ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   32 | __va_arg_pack ());
      | ~~~~~~~~~~~~~~~~~
comskip.c: In function ‘OpenOutputFiles’:
comskip.c:6547:30: warning: �-Wformat-overflow=e[me[K][]]
 6547 | sprintf(filename, "%s.avs", mpegfilename);
      | ^~~~
In function ‘sprintf’,
    inlined from ‘OpenOutputFiles’ at comskip.c:6547:9:
/usr/include/bits/stdio2.h:30:10: note: ‘ __builtin___ sprintf_chk’ output between 5 and 260 bytes into a destination of size 256
   30 | return __builtin___ sprintf_chk ( __s,__ USE_FORTIFY_LEVEL - 1,
      | ^ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   31 | __glibc_objsize (__s), __fmt,
      | ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   32 | __va_arg_pack ());
      | ~~~~~~~~~~~~~~~~~
comskip.c: In function ‘OpenOutputFiles’:
comskip.c:6566:30: warning: �-Wformat-overflow=e[me[K][]]
 6566 | sprintf(filename, "%s.wme", outbasename);
      | ^~~~
In function ‘sprintf’,
    inlined from ‘OpenOutputFiles’ at comskip.c:6566:9:
/usr/include/bits/stdio2.h:30:10: note: ‘ __builtin___ sprintf_chk’ output between 5 and 260 bytes into a destination of size 256
   30 | return __builtin___ sprintf_chk ( __s,__ USE_FORTIFY_LEVEL - 1,
      | ^ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   31 | __glibc_objsize (__s), __fmt,
      | ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   32 | __va_arg_pack ());
      | ~~~~~~~~~~~~~~~~~
comskip.c: In function ‘OpenOutputFiles’:
comskip.c:6582:30: warning: �-Wformat-overflow=e[me[K][]]
 6582 | sprintf(filename, "%s.mls", outbasename);
      | ^~~~
In function ‘sprintf’,
    inlined from ‘OpenOutputFiles’ at comskip.c:6582:9:
/usr/include/bits/stdio2.h:30:10: note: ‘ __builtin___ sprintf_chk’ output between 5 and 260 bytes into a destination of size 256
   30 | return __builtin___ sprintf_chk ( __s,__ USE_FORTIFY_LEVEL - 1,
      | ^ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   31 | __glibc_objsize (__s), __fmt,
      | ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   32 | __va_arg_pack ());
      | ~~~~~~~~~~~~~~~~~
comskip.c: In function ‘OpenOutputFiles’:
comskip.c:6604:30: warning: �-Wformat-overflow=e[me[K][]]
 6604 | sprintf(filename, "%s_mpgtx.bat", outbasename);
      | ^ ~~~~~~~~~
In function ‘sprintf’,
    inlined from ‘OpenOutputFiles’ at comskip.c:6604:9:
/usr/include/bits/stdio2.h:30:10: note: ‘ __builtin___ sprintf_chk’ output between 11 and 266 bytes into a destination of size 256
   30 | return __builtin___ sprintf_chk ( __s,__ USE_FORTIFY_LEVEL - 1,
      | ^ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   31 | __glibc_objsize (__s), __fmt,
      | ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   32 | __va_arg_pack ());
      | ~~~~~~~~~~~~~~~~~
comskip.c: In function ‘OpenOutputFiles’:
comskip.c:6621:30: warning: �-Wformat-overflow=e[me[K][]]
 6621 | sprintf(filename, "%s_dvrcut.bat", outbasename);
      | ^ ~~~~~~~~~~
In function ‘sprintf’,
    inlined from ‘OpenOutputFiles’ at comskip.c:6621:9:
/usr/include/bits/stdio2.h:30:10: note: ‘ __builtin___ sprintf_chk’ output between 12 and 267 bytes into a destination of size 256
   30 | return __builtin___ sprintf_chk ( __s,__ USE_FORTIFY_LEVEL - 1,
      | ^ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   31 | __glibc_objsize (__s), __fmt,
      | ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   32 | __va_arg_pack ());
      | ~~~~~~~~~~~~~~~~~
comskip.c: In function ‘OpenOutputFiles’:
comskip.c:6640:30: warning: �-Wformat-overflow=e[me[K][]]
 6640 | sprintf(filename, "%s.xml", outbasename);
      | ^~~~
In function ‘sprintf’,
    inlined from ‘OpenOutputFiles’ at comskip.c:6640:9:
/usr/include/bits/stdio2.h:30:10: note: ‘ __builtin___ sprintf_chk’ output between 5 and 260 bytes into a destination of size 256
   30 | return __builtin___ sprintf_chk ( __s,__ USE_FORTIFY_LEVEL - 1,
      | ^ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   31 | __glibc_objsize (__s), __fmt,
      | ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   32 | __va_arg_pack ());
      | ~~~~~~~~~~~~~~~~~
comskip.c: In function ‘OpenOutputFiles’:
comskip.c:6656:30: warning: �-Wformat-overflow=e[me[K][]]
 6656 | sprintf(filename, "%s_mpeg2schnitt.bat", inbasename);
      | ^ ~~~~~~~~~~~~~~~~
In function ‘sprintf’,
    inlined from ‘OpenOutputFiles’ at comskip.c:6656:9:
/usr/include/bits/stdio2.h:30:10: note: ‘ __builtin___ sprintf_chk’ output between 18 and 273 bytes into a destination of size 256
   30 | return __builtin___ sprintf_chk ( __s,__ USE_FORTIFY_LEVEL - 1,
      | ^ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   31 | __glibc_objsize (__s), __fmt,
      | ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   32 | __va_arg_pack ());
      | ~~~~~~~~~~~~~~~~~
comskip.c: In function ‘OpenOutputFiles’:
comskip.c:6697:38: warning: �-Wformat-overflow=e[me[K][]]
 6697 | sprintf(filename, "%s.mkvtoolnix.chapters", outbasename);
      | ^ ~~~~~~~~~~~~~~~~~~~
In function ‘sprintf’,
    inlined from ‘OpenOutputFiles’ at comskip.c:6697:3:
/usr/include/bits/stdio2.h:30:10: note: ‘ __builtin___ sprintf_chk’ output between 21 and 276 bytes into a destination of size 256
   30 | return __builtin___ sprintf_chk ( __s,__ USE_FORTIFY_LEVEL - 1,
      | ^ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   31 | __glibc_objsize (__s), __fmt,
      | ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   32 | __va_arg_pack ());
      | ~~~~~~~~~~~~~~~~~
comskip.c: In function ‘OpenOutputFiles’:
comskip.c:6745:38: warning: �-Wformat-overflow=e[me[K][]]
 6745 | sprintf(filename, "%s.mkvtoolnix.tags", outbasename);
      | ^ ~~~~~~~~~~~~~~~
In function ‘sprintf’,
    inlined from ‘OpenOutputFiles’ at comskip.c:6745:3:
/usr/include/bits/stdio2.h:30:10: note: ‘ __builtin___ sprintf_chk’ output between 17 and 272 bytes into a destination of size 256
   30 | return __builtin___ sprintf_chk ( __s,__ USE_FORTIFY_LEVEL - 1,
      | ^ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   31 | __glibc_objsize (__s), __fmt,
      | ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   32 | __va_arg_pack ());
      | ~~~~~~~~~~~~~~~~~
comskip.c: In function ‘FindString’:
comskip.c:8354:31: warning: �-Wformat-overflow=e[me[K][]]
 8354 | sprintf(tmp, "%s\"%s\"\n", str2, foundText);
      | ^~ ~~~~~~~~~
In function ‘sprintf’,
    inlined from ‘FindString’ at comskip.c:8354:13:
/usr/include/bits/stdio2.h:30:10: note: ‘ __builtin___ sprintf_chk’ output 4 or more bytes (assuming 1027) into a destination of size 255
   30 | return __builtin___ sprintf_chk ( __s,__ USE_FORTIFY_LEVEL - 1,
      | ^ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   31 | __glibc_objsize (__s), __fmt,
      | ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   32 | __va_arg_pack ());
      | ~~~~~~~~~~~~~~~~~
comskip.c: In function ‘AddXDS’:
comskip.c:14840:25: warning: �-Wstringop-truncatione[me[K][]]
14840 | strncpy(XDS_block[XDS_block_count].name, (const char*) &XDSbuf[2], n);
      | ^
comskip.c: In function ‘OutputBlocks’:
comskip.c:7687:30: warning: �-Wformat-overflow=e[me[K][]]
 7687 | sprintf(filename, "%s.VPrj", outbasename);
      | ^ ~~~~
In function ‘sprintf’,
    inlined from ‘OutputBlocks’ at comskip.c:7687:9:
/usr/include/bits/stdio2.h:30:10: note: ‘ __builtin___ sprintf_chk’ output between 6 and 261 bytes into a destination of size 256
   30 | return __builtin___ sprintf_chk ( __s,__ USE_FORTIFY_LEVEL - 1,
      | ^ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   31 | __glibc_objsize (__s), __fmt,
      | ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   32 | __va_arg_pack ());
      | ~~~~~~~~~~~~~~~~~
comskip.c: In function ‘OutputBlocks’:
comskip.c:7701:30: warning: �-Wformat-overflow=e[me[K][]]
 7701 | sprintf(filename, "%s.VPrj", outbasename);
      | ^ ~~~~
In function ‘sprintf’,
    inlined from ‘OutputBlocks’ at comskip.c:7701:9:
/usr/include/bits/stdio2.h:30:10: note: ‘ __builtin___ sprintf_chk’ output between 6 and 261 bytes into a destination of size 256
   30 | return __builtin___ sprintf_chk ( __s,__ USE_FORTIFY_LEVEL - 1,
      | ^ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   31 | __glibc_objsize (__s), __fmt,
      | ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   32 | __va_arg_pack ());
      | ~~~~~~~~~~~~~~~~~
comskip.c: In function ‘OutputBlocks’:
comskip.c:7803:30: warning: �-Wformat-overflow=e[me[K][]]
 7803 | sprintf(filename, "%s.tun", workbasename);
      | ^~~~
In function ‘sprintf’,
    inlined from ‘OutputBlocks’ at comskip.c:7803:9:
/usr/include/bits/stdio2.h:30:10: note: ‘ __builtin___ sprintf_chk’ output between 5 and 260 bytes into a destination of size 256
   30 | return __builtin___ sprintf_chk ( __s,__ USE_FORTIFY_LEVEL - 1,
      | ^ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   31 | __glibc_objsize (__s), __fmt,
      | ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   32 | __va_arg_pack ());
      | ~~~~~~~~~~~~~~~~~
comskip.c: In function ‘AddXDS’:
comskip.c:14840:25: warning: �-Wstringop-truncatione[me[K][]]
14840 | strncpy(XDS_block[XDS_block_count].name, (const char*) &XDSbuf[2], n);
      | ^
comskip.c: In function ‘OutputBlocks’:
comskip.c:7687:30: warning: �-Wformat-overflow=e[me[K][]]
 7687 | sprintf(filename, "%s.VPrj", outbasename);
      | ^ ~~~~
In function ‘sprintf’,
    inlined from ‘OutputBlocks’ at comskip.c:7687:9:
/usr/include/bits/stdio2.h:30:10: note: ‘ __builtin___ sprintf_chk’ output between 6 and 261 bytes into a destination of size 256
   30 | return __builtin___ sprintf_chk ( __s,__ USE_FORTIFY_LEVEL - 1,
      | ^ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   31 | __glibc_objsize (__s), __fmt,
      | ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   32 | __va_arg_pack ());
      | ~~~~~~~~~~~~~~~~~
comskip.c: In function ‘OutputBlocks’:
comskip.c:7701:30: warning: �-Wformat-overflow=e[me[K][]]
 7701 | sprintf(filename, "%s.VPrj", outbasename);
      | ^ ~~~~
In function ‘sprintf’,
    inlined from ‘OutputBlocks’ at comskip.c:7701:9:
/usr/include/bits/stdio2.h:30:10: note: ‘ __builtin___ sprintf_chk’ output between 6 and 261 bytes into a destination of size 256
   30 | return __builtin___ sprintf_chk ( __s,__ USE_FORTIFY_LEVEL - 1,
      | ^ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   31 | __glibc_objsize (__s), __fmt,
      | ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   32 | __va_arg_pack ());
      | ~~~~~~~~~~~~~~~~~
comskip.c: In function ‘OutputBlocks’:
comskip.c:7803:30: warning: �-Wformat-overflow=e[me[K][]]
 7803 | sprintf(filename, "%s.tun", workbasename);
      | ^~~~
In function ‘sprintf’,
    inlined from ‘OutputBlocks’ at comskip.c:7803:9:
/usr/include/bits/stdio2.h:30:10: note: ‘ __builtin___ sprintf_chk’ output between 5 and 260 bytes into a destination of size 256
   30 | return __builtin___ sprintf_chk ( __s,__ USE_FORTIFY_LEVEL - 1,
      | ^ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   31 | __glibc_objsize (__s), __fmt,
      | ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   32 | __va_arg_pack ());
      | ~~~~~~~~~~~~~~~~~
comskip.c: In function ‘BuildMasterCommList.part.0’:
comskip.c:4657:30: warning: �-Wformat-overflow=e[me[K][]]
 4657 | sprintf(temp, "%s.ccno", workbasename);
      | ^ ~~~~
In function ‘sprintf’,
    inlined from ‘BuildMasterCommList.part.0’ at comskip.c:4657:13:
/usr/include/bits/stdio2.h:30:10: note: ‘ __builtin___ sprintf_chk’ output between 6 and 261 bytes into a destination of size 256
   30 | return __builtin___ sprintf_chk ( __s,__ USE_FORTIFY_LEVEL - 1,
      | ^ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   31 | __glibc_objsize (__s), __fmt,
      | ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   32 | __va_arg_pack ());
      | ~~~~~~~~~~~~~~~~~
comskip.c: In function ‘BuildMasterCommList.part.0’:
comskip.c:4660:30: warning: �-Wformat-overflow=e[me[K][]]
 4660 | sprintf(temp, "%s.ccyes", workbasename);
      | ^ ~~~~~
In function ‘sprintf’,
    inlined from ‘BuildMasterCommList.part.0’ at comskip.c:4660:13:
/usr/include/bits/stdio2.h:30:10: note: ‘ __builtin___ sprintf_chk’ output between 7 and 262 bytes into a destination of size 256
   30 | return __builtin___ sprintf_chk ( __s,__ USE_FORTIFY_LEVEL - 1,
      | ^ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   31 | __glibc_objsize (__s), __fmt,
      | ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   32 | __va_arg_pack ());
      | ~~~~~~~~~~~~~~~~~
comskip.c: In function ‘BuildMasterCommList.part.0’:
comskip.c:4649:30: warning: �-Wformat-overflow=e[me[K][]]
 4649 | sprintf(temp, "%s.ccyes", workbasename);
      | ^ ~~~~~
In function ‘sprintf’,
    inlined from ‘BuildMasterCommList.part.0’ at comskip.c:4649:13:
/usr/include/bits/stdio2.h:30:10: note: ‘ __builtin___ sprintf_chk’ output between 7 and 262 bytes into a destination of size 256
   30 | return __builtin___ sprintf_chk ( __s,__ USE_FORTIFY_LEVEL - 1,
      | ^ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   31 | __glibc_objsize (__s), __fmt,
      | ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   32 | __va_arg_pack ());
      | ~~~~~~~~~~~~~~~~~
comskip.c: In function ‘BuildMasterCommList.part.0’:
comskip.c:4652:30: warning: �-Wformat-overflow=e[me[K][]]
 4652 | sprintf(temp, "%s.ccno", workbasename);
      | ^ ~~~~
In function ‘sprintf’,
    inlined from ‘BuildMasterCommList.part.0’ at comskip.c:4652:13:
/usr/include/bits/stdio2.h:30:10: note: ‘ __builtin___ sprintf_chk’ output between 6 and 261 bytes into a destination of size 256
   30 | return __builtin___ sprintf_chk ( __s,__ USE_FORTIFY_LEVEL - 1,
      | ^ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   31 | __glibc_objsize (__s), __fmt,
      | ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   32 | __va_arg_pack ());
      | ~~~~~~~~~~~~~~~~~
comskip.c: In function ‘BuildCommListAsYouGo’:
comskip.c:16116:38: warning: �-Wformat-overflow=e[me[K][]]
16116 | sprintf(filename, "%s.edl", outbasename);
      | ^~~~
In function ‘sprintf’,
    inlined from ‘BuildCommListAsYouGo’ at comskip.c:16116:17:
/usr/include/bits/stdio2.h:30:10: note: ‘ __builtin___ sprintf_chk’ output between 5 and 260 bytes into a destination of size 255
   30 | return __builtin___ sprintf_chk ( __s,__ USE_FORTIFY_LEVEL - 1,
      | ^ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   31 | __glibc_objsize (__s), __fmt,
      | ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   32 | __va_arg_pack ());
      | ~~~~~~~~~~~~~~~~~
comskip.c: In function ‘BuildCommListAsYouGo’:
comskip.c:16131:38: warning: �-Wformat-overflow=e[me[K][]]
16131 | sprintf(filename, "%s.live", outbasename);
      | ^ ~~~~
In function ‘sprintf’,
    inlined from ‘BuildCommListAsYouGo’ at comskip.c:16131:17:
/usr/include/bits/stdio2.h:30:10: note: ‘ __builtin___ sprintf_chk’ output between 6 and 261 bytes into a destination of size 255
   30 | return __builtin___ sprintf_chk ( __s,__ USE_FORTIFY_LEVEL - 1,
      | ^ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   31 | __glibc_objsize (__s), __fmt,
      | ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   32 | __va_arg_pack ());
      | ~~~~~~~~~~~~~~~~~
comskip.c: In function ‘BuildCommListAsYouGo’:
comskip.c:16147:38: warning: �-Wformat-overflow=e[me[K][]]
16147 | sprintf(filename, "%s.xml", outbasename);
      | ^~~~
In function ‘sprintf’,
    inlined from ‘BuildCommListAsYouGo’ at comskip.c:16147:17:
/usr/include/bits/stdio2.h:30:10: note: ‘ __builtin___ sprintf_chk’ output between 5 and 260 bytes into a destination of size 255
   30 | return __builtin___ sprintf_chk ( __s,__ USE_FORTIFY_LEVEL - 1,
      | ^ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   31 | __glibc_objsize (__s), __fmt,
      | ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   32 | __va_arg_pack ());
      | ~~~~~~~~~~~~~~~~~
comskip.c: In function ‘BuildCommListAsYouGo’:
comskip.c:16256:38: warning: �-Wformat-overflow=e[me[K][]]
16256 | sprintf(filename, "%s.incommercial", workbasename);
      | ^ ~~~~~~~~~~~~
In function ‘sprintf’,
    inlined from ‘BuildCommListAsYouGo’ at comskip.c:16256:17:
/usr/include/bits/stdio2.h:30:10: note: ‘ __builtin___ sprintf_chk’ output between 14 and 269 bytes into a destination of size 255
   30 | return __builtin___ sprintf_chk ( __s,__ USE_FORTIFY_LEVEL - 1,
      | ^ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   31 | __glibc_objsize (__s), __fmt,
      | ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   32 | __va_arg_pack ());
      | ~~~~~~~~~~~~~~~~~
comskip.c: In function ‘dump_audio_start’:
comskip.c:16447:26: warning: �-Wformat-overflow=e[me[K][]]
16447 | sprintf(temp, "%s.mp2", workbasename);
      | ^~~~
In function ‘sprintf’,
    inlined from ‘dump_audio_start’ at comskip.c:16447:9:
/usr/include/bits/stdio2.h:30:10: note: ‘ __builtin___ sprintf_chk’ output between 5 and 260 bytes into a destination of size 256
   30 | return __builtin___ sprintf_chk ( __s,__ USE_FORTIFY_LEVEL - 1,
      | ^ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   31 | __glibc_objsize (__s), __fmt,
      | ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   32 | __va_arg_pack ());
      | ~~~~~~~~~~~~~~~~~
comskip.c: In function ‘dump_video_start’:
comskip.c:16469:26: warning: �-Wformat-overflow=e[me[K][]]
16469 | sprintf(temp, "%s.m2v", workbasename);
      | ^~~~
In function ‘sprintf’,
    inlined from ‘dump_video_start’ at comskip.c:16469:9:
/usr/include/bits/stdio2.h:30:10: note: ‘ __builtin___ sprintf_chk’ output between 5 and 260 bytes into a destination of size 256
   30 | return __builtin___ sprintf_chk ( __s,__ USE_FORTIFY_LEVEL - 1,
      | ^ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   31 | __glibc_objsize (__s), __fmt,
      | ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   32 | __va_arg_pack ());
      | ~~~~~~~~~~~~~~~~~
comskip.c: In function ‘BuildMasterCommList.part.0’:
comskip.c:4657:30: warning: �-Wformat-overflow=e[me[K][]]
 4657 | sprintf(temp, "%s.ccno", workbasename);
      | ^ ~~~~
In function ‘sprintf’,
    inlined from ‘BuildMasterCommList.part.0’ at comskip.c:4657:13:
/usr/include/bits/stdio2.h:30:10: note: ‘ __builtin___ sprintf_chk’ output between 6 and 261 bytes into a destination of size 256
   30 | return __builtin___ sprintf_chk ( __s,__ USE_FORTIFY_LEVEL - 1,
      | ^ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   31 | __glibc_objsize (__s), __fmt,
      | ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   32 | __va_arg_pack ());
      | ~~~~~~~~~~~~~~~~~
comskip.c: In function ‘BuildMasterCommList.part.0’:
comskip.c:4660:30: warning: �-Wformat-overflow=e[me[K][]]
 4660 | sprintf(temp, "%s.ccyes", workbasename);
      | ^ ~~~~~
In function ‘sprintf’,
    inlined from ‘BuildMasterCommList.part.0’ at comskip.c:4660:13:
/usr/include/bits/stdio2.h:30:10: note: ‘ __builtin___ sprintf_chk’ output between 7 and 262 bytes into a destination of size 256
   30 | return __builtin___ sprintf_chk ( __s,__ USE_FORTIFY_LEVEL - 1,
      | ^ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   31 | __glibc_objsize (__s), __fmt,
      | ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   32 | __va_arg_pack ());
      | ~~~~~~~~~~~~~~~~~
comskip.c: In function ‘BuildMasterCommList.part.0’:
comskip.c:4649:30: warning: �-Wformat-overflow=e[me[K][]]
 4649 | sprintf(temp, "%s.ccyes", workbasename);
      | ^ ~~~~~
In function ‘sprintf’,
    inlined from ‘BuildMasterCommList.part.0’ at comskip.c:4649:13:
/usr/include/bits/stdio2.h:30:10: note: ‘ __builtin___ sprintf_chk’ output between 7 and 262 bytes into a destination of size 256
   30 | return __builtin___ sprintf_chk ( __s,__ USE_FORTIFY_LEVEL - 1,
      | ^ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   31 | __glibc_objsize (__s), __fmt,
      | ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   32 | __va_arg_pack ());
      | ~~~~~~~~~~~~~~~~~
comskip.c: In function ‘BuildMasterCommList.part.0’:
comskip.c:4652:30: warning: �-Wformat-overflow=e[me[K][]]
 4652 | sprintf(temp, "%s.ccno", workbasename);
      | ^ ~~~~
In function ‘sprintf’,
    inlined from ‘BuildMasterCommList.part.0’ at comskip.c:4652:13:
/usr/include/bits/stdio2.h:30:10: note: ‘ __builtin___ sprintf_chk’ output between 6 and 261 bytes into a destination of size 256
   30 | return __builtin___ sprintf_chk ( __s,__ USE_FORTIFY_LEVEL - 1,
      | ^ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   31 | __glibc_objsize (__s), __fmt,
      | ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   32 | __va_arg_pack ());
      | ~~~~~~~~~~~~~~~~~
comskip.c: In function ‘BuildCommListAsYouGo’:
comskip.c:16116:38: warning: �-Wformat-overflow=e[me[K][]]
16116 | sprintf(filename, "%s.edl", outbasename);
      | ^~~~
In function ‘sprintf’,
    inlined from ‘BuildCommListAsYouGo’ at comskip.c:16116:17:
/usr/include/bits/stdio2.h:30:10: note: ‘ __builtin___ sprintf_chk’ output between 5 and 260 bytes into a destination of size 255
   30 | return __builtin___ sprintf_chk ( __s,__ USE_FORTIFY_LEVEL - 1,
      | ^ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   31 | __glibc_objsize (__s), __fmt,
      | ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   32 | __va_arg_pack ());
      | ~~~~~~~~~~~~~~~~~
comskip.c: In function ‘BuildCommListAsYouGo’:
comskip.c:16131:38: warning: �-Wformat-overflow=e[me[K][]]
16131 | sprintf(filename, "%s.live", outbasename);
      | ^ ~~~~
In function ‘sprintf’,
    inlined from ‘BuildCommListAsYouGo’ at comskip.c:16131:17:
/usr/include/bits/stdio2.h:30:10: note: ‘ __builtin___ sprintf_chk’ output between 6 and 261 bytes into a destination of size 255
   30 | return __builtin___ sprintf_chk ( __s,__ USE_FORTIFY_LEVEL - 1,
      | ^ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   31 | __glibc_objsize (__s), __fmt,
      | ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   32 | __va_arg_pack ());
      | ~~~~~~~~~~~~~~~~~
comskip.c: In function ‘BuildCommListAsYouGo’:
comskip.c:16147:38: warning: �-Wformat-overflow=e[me[K][]]
16147 | sprintf(filename, "%s.xml", outbasename);
      | ^~~~
In function ‘sprintf’,
    inlined from ‘BuildCommListAsYouGo’ at comskip.c:16147:17:
/usr/include/bits/stdio2.h:30:10: note: ‘ __builtin___ sprintf_chk’ output between 5 and 260 bytes into a destination of size 255
   30 | return __builtin___ sprintf_chk ( __s,__ USE_FORTIFY_LEVEL - 1,
      | ^ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   31 | __glibc_objsize (__s), __fmt,
      | ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   32 | __va_arg_pack ());
      | ~~~~~~~~~~~~~~~~~
comskip.c: In function ‘BuildCommListAsYouGo’:
comskip.c:16256:38: warning: �-Wformat-overflow=e[me[K][]]
16256 | sprintf(filename, "%s.incommercial", workbasename);
      | ^ ~~~~~~~~~~~~
In function ‘sprintf’,
    inlined from ‘BuildCommListAsYouGo’ at comskip.c:16256:17:
/usr/include/bits/stdio2.h:30:10: note: ‘ __builtin___ sprintf_chk’ output between 14 and 269 bytes into a destination of size 255
   30 | return __builtin___ sprintf_chk ( __s,__ USE_FORTIFY_LEVEL - 1,
      | ^ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   31 | __glibc_objsize (__s), __fmt,
      | ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   32 | __va_arg_pack ());
      | ~~~~~~~~~~~~~~~~~
comskip.c: In function ‘LoadSettings’:
comskip.c:9160:39: warning: �-Wformat-overflow=e[me[K][]]
 9160 | sprintf(inifilename, "%s%ccomskip.ini", HomeDir, PATH_SEPARATOR);
      | ^ ~~~~~~~~~~
In function ‘sprintf’,
    inlined from ‘LoadSettings’ at comskip.c:9160:13:
/usr/include/bits/stdio2.h:30:10: note: ‘ __builtin___ sprintf_chk’ output between 13 and 268 bytes into a destination of size 256
   30 | return __builtin___ sprintf_chk ( __s,__ USE_FORTIFY_LEVEL - 1,
      | ^ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   31 | __glibc_objsize (__s), __fmt,
      | ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   32 | __va_arg_pack ());
      | ~~~~~~~~~~~~~~~~~
comskip.c: In function ‘LoadSettings’:
comskip.c:9163:35: warning: �-Wformat-overflow=e[me[K][]]
 9163 | sprintf(exefilename, "%s%ccomskip.exe", HomeDir, PATH_SEPARATOR);
      | ^ ~~~~~~~~~~
In function ‘sprintf’,
    inlined from ‘LoadSettings’ at comskip.c:9163:9:
/usr/include/bits/stdio2.h:30:10: note: ‘ __builtin___ sprintf_chk’ output between 13 and 268 bytes into a destination of size 256
   30 | return __builtin___ sprintf_chk ( __s,__ USE_FORTIFY_LEVEL - 1,
      | ^ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   31 | __glibc_objsize (__s), __fmt,
      | ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   32 | __va_arg_pack ());
      | ~~~~~~~~~~~~~~~~~
comskip.c: In function ‘LoadSettings’:
comskip.c:9164:36: warning: �-Wformat-overflow=e[me[K][]]
 9164 | sprintf(dictfilename, "%s%ccomskip.dictionary", HomeDir, PATH_SEPARATOR);
      | ^ ~~~~~~~~~~~~~~~~~
In function ‘sprintf’,
    inlined from ‘LoadSettings’ at comskip.c:9164:9:
/usr/include/bits/stdio2.h:30:10: note: ‘ __builtin___ sprintf_chk’ output between 20 and 275 bytes into a destination of size 256
   30 | return __builtin___ sprintf_chk ( __s,__ USE_FORTIFY_LEVEL - 1,
      | ^ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   31 | __glibc_objsize (__s), __fmt,
      | ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   32 | __va_arg_pack ());
      | ~~~~~~~~~~~~~~~~~
comskip.c: In function ‘dump_audio_start’:
comskip.c:16447:26: warning: �-Wformat-overflow=e[me[K][]]
16447 | sprintf(temp, "%s.mp2", workbasename);
      | ^~~~
In function ‘sprintf’,
    inlined from ‘dump_audio_start’ at comskip.c:16447:9:
/usr/include/bits/stdio2.h:30:10: note: ‘ __builtin___ sprintf_chk’ output between 5 and 260 bytes into a destination of size 256
   30 | return __builtin___ sprintf_chk ( __s,__ USE_FORTIFY_LEVEL - 1,
      | ^ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   31 | __glibc_objsize (__s), __fmt,
      | ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   32 | __va_arg_pack ());
      | ~~~~~~~~~~~~~~~~~
comskip.c: In function ‘dump_video_start’:
comskip.c:16469:26: warning: �-Wformat-overflow=e[me[K][]]
16469 | sprintf(temp, "%s.m2v", workbasename);
      | ^~~~
In function ‘sprintf’,
    inlined from ‘dump_video_start’ at comskip.c:16469:9:
/usr/include/bits/stdio2.h:30:10: note: ‘ __builtin___ sprintf_chk’ output between 5 and 260 bytes into a destination of size 256
   30 | return __builtin___ sprintf_chk ( __s,__ USE_FORTIFY_LEVEL - 1,
      | ^ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   31 | __glibc_objsize (__s), __fmt,
      | ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   32 | __va_arg_pack ());
      | ~~~~~~~~~~~~~~~~~
mv -f .deps/comskip-comskip.Tpo .deps/comskip-comskip.Po
comskip.c: In function ‘LoadSettings’:
comskip.c:9160:39: warning: �-Wformat-overflow=e[me[K][]]
 9160 | sprintf(inifilename, "%s%ccomskip.ini", HomeDir, PATH_SEPARATOR);
      | ^ ~~~~~~~~~~
In function ‘sprintf’,
    inlined from ‘LoadSettings’ at comskip.c:9160:13:
/usr/include/bits/stdio2.h:30:10: note: ‘ __builtin___ sprintf_chk’ output between 13 and 268 bytes into a destination of size 256
   30 | return __builtin___ sprintf_chk ( __s,__ USE_FORTIFY_LEVEL - 1,
      | ^ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   31 | __glibc_objsize (__s), __fmt,
      | ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   32 | __va_arg_pack ());
      | ~~~~~~~~~~~~~~~~~
comskip.c: In function ‘LoadSettings’:
comskip.c:9163:35: warning: �-Wformat-overflow=e[me[K][]]
 9163 | sprintf(exefilename, "%s%ccomskip.exe", HomeDir, PATH_SEPARATOR);
      | ^ ~~~~~~~~~~
In function ‘sprintf’,
    inlined from ‘LoadSettings’ at comskip.c:9163:9:
/usr/include/bits/stdio2.h:30:10: note: ‘ __builtin___ sprintf_chk’ output between 13 and 268 bytes into a destination of size 256
   30 | return __builtin___ sprintf_chk ( __s,__ USE_FORTIFY_LEVEL - 1,
      | ^ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   31 | __glibc_objsize (__s), __fmt,
      | ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   32 | __va_arg_pack ());
      | ~~~~~~~~~~~~~~~~~
comskip.c: In function ‘LoadSettings’:
comskip.c:9164:36: warning: �-Wformat-overflow=e[me[K][]]
 9164 | sprintf(dictfilename, "%s%ccomskip.dictionary", HomeDir, PATH_SEPARATOR);
      | ^ ~~~~~~~~~~~~~~~~~
In function ‘sprintf’,
    inlined from ‘LoadSettings’ at comskip.c:9164:9:
/usr/include/bits/stdio2.h:30:10: note: ‘ __builtin___ sprintf_chk’ output between 20 and 275 bytes into a destination of size 256
   30 | return __builtin___ sprintf_chk ( __s,__ USE_FORTIFY_LEVEL - 1,
      | ^ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   31 | __glibc_objsize (__s), __fmt,
      | ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
   32 | __va_arg_pack ());
      | ~~~~~~~~~~~~~~~~~
mv -f .deps/comskip_gui-comskip.Tpo .deps/comskip_gui-comskip.Po
 * ERROR: media-tv/Comskip-0_p20250418::om failed (compile phase):
 * emake failed

```

---

<div class="post-metadata">

**Author:** ![drzoidberg33](https://sea1.discourse-cdn.com/plex/user_avatar/forums.plex.tv/drzoidberg33/32/4184_2.png) [@drzoidberg33](https://forums.plex.tv/u/drzoidberg33)\
**Post date:** [January 21, 2026, 7:10am UTC](https://forums.plex.tv/t/buffer-overflows-in-plex-commercial-skipper/935638/2 "2026-01-21T07:10:19Z")

</div>

I’m assuming you sent this to [security@plex.tv](mailto:security@plex.tv) as outlined here: [https://support.plex.tv/articles/reporting-security-issues/](https://support.plex.tv/articles/reporting-security-issues/) ?

When was your report submitted and does it demonstrate a clear reproducible security concern?

Low quality reports might be ignored if they don’t include clear steps, impact and proof of concept code. If you feel your initial report satisfies this then feel free to DM me with the original report and I’ll bring it up with the security team.

---

<div class="post-metadata">

**Author:** ![Gloppie](https://avatars.discourse-cdn.com/v4/letter/g/74df32/32.png) [@Gloppie](https://forums.plex.tv/u/Gloppie)\
**Post date:** [January 26, 2026, 9:26pm UTC](https://forums.plex.tv/t/buffer-overflows-in-plex-commercial-skipper/935638/3 "2026-01-26T21:26:34Z")

</div>

Yes, I responded there and was ignored. Please update this to work with the new ffmpeg.

---

<div class="post-metadata">

**Author:** ![drzoidberg33](https://sea1.discourse-cdn.com/plex/user_avatar/forums.plex.tv/drzoidberg33/32/4184_2.png) [@drzoidberg33](https://forums.plex.tv/u/drzoidberg33)\
**Post date:** [January 27, 2026, 8:39am UTC](https://forums.plex.tv/t/buffer-overflows-in-plex-commercial-skipper/935638/4 "2026-01-27T08:39:47Z")

</div>

> [@drzoidberg33](#):
>
> When was your report submitted and does it demonstrate a clear reproducible security concern?

You haven’t answered this yet.

---

<div class="post-metadata">

**Author:** ![Gloppie](https://avatars.discourse-cdn.com/v4/letter/g/74df32/32.png) [@Gloppie](https://forums.plex.tv/u/Gloppie)\
**Post date:** [January 27, 2026, 8:37pm UTC](https://forums.plex.tv/t/buffer-overflows-in-plex-commercial-skipper/935638/5 "2026-01-27T20:37:12Z")

</div>

maybe go through your own info.

---

<div class="post-metadata">

**Author:** ![Gloppie](https://avatars.discourse-cdn.com/v4/letter/g/74df32/32.png) [@Gloppie](https://forums.plex.tv/u/Gloppie)\
**Post date:** [January 28, 2026, 9:03pm UTC](https://forums.plex.tv/t/buffer-overflows-in-plex-commercial-skipper/935638/6 "2026-01-28T21:03:38Z")

</div>

Is this fixed in the update?

---

<div class="post-metadata">

**Author:** ![Gloppie](https://avatars.discourse-cdn.com/v4/letter/g/74df32/32.png) [@Gloppie](https://forums.plex.tv/u/Gloppie)\
**Post date:** [February 17, 2026, 9:32pm UTC](https://forums.plex.tv/t/buffer-overflows-in-plex-commercial-skipper/935638/7 "2026-02-17T21:32:40Z")

</div>

Is this fixed in the update?

---

<div class="post-metadata">

**Author:** ![Gloppie](https://avatars.discourse-cdn.com/v4/letter/g/74df32/32.png) [@Gloppie](https://forums.plex.tv/u/Gloppie)\
**Post date:** [February 17, 2026, 10:22pm UTC](https://forums.plex.tv/t/buffer-overflows-in-plex-commercial-skipper/935638/8 "2026-02-17T22:22:14Z")

</div>

I think this is five updates since I made this public.

---

<div class="post-metadata">

**Author:** ![Atomatth](https://sea1.discourse-cdn.com/plex/user_avatar/forums.plex.tv/atomatth/32/314355_2.png) [@Atomatth](https://forums.plex.tv/u/Atomatth)\
**Post date:** [February 18, 2026, 4:03pm UTC](https://forums.plex.tv/t/buffer-overflows-in-plex-commercial-skipper/935638/9 "2026-02-18T16:03:04Z")

</div>

> [@Gloppie](#):
>
> Is this fixed in the update?

You haven’t provided enough information to be actionable. Please resubmit to [security@plex.tv](mailto:security@plex.tv) and be sure to follow the requirements outlined in [https://support.plex.tv/articles/reporting-security-issues/](https://support.plex.tv/articles/reporting-security-issues/).

> [@drzoidberg33](#):
>
> If you feel your initial report satisfies this then feel free to DM me with the original report and I’ll bring it up with the security team.

Feel free to DM me or @drzoidberg33 with clear reproducible steps. We are willing to address your concerns but you need to provide reproducible steps. Help us help you.

---

<div class="post-metadata">

**Author:** ![Gloppie](https://avatars.discourse-cdn.com/v4/letter/g/74df32/32.png) [@Gloppie](https://forums.plex.tv/u/Gloppie)\
**Post date:** [February 20, 2026, 2:23am UTC](https://forums.plex.tv/t/buffer-overflows-in-plex-commercial-skipper/935638/10 "2026-02-20T02:23:18Z")

</div>

Are you denying a problem when you can clearly see issues?

---

<div class="post-metadata">

**Author:** ![Atomatth](https://sea1.discourse-cdn.com/plex/user_avatar/forums.plex.tv/atomatth/32/314355_2.png) [@Atomatth](https://forums.plex.tv/u/Atomatth)\
**Post date:** [February 20, 2026, 2:37pm UTC](https://forums.plex.tv/t/buffer-overflows-in-plex-commercial-skipper/935638/11 "2026-02-20T14:37:57Z")

</div>

I’m not denying anything. You haven’t clearly identified what the issue is and how to reproduce it. Stating “You have an issue, go find it” is not helpful. If you are seeing an issue, properly report it with logs and steps to reproduce it. Again, help us help you.

---

<div class="post-metadata">

**Author:** ![Gloppie](https://avatars.discourse-cdn.com/v4/letter/g/74df32/32.png) [@Gloppie](https://forums.plex.tv/u/Gloppie)\
**Post date:** [March 12, 2026, 11:05pm UTC](https://forums.plex.tv/t/buffer-overflows-in-plex-commercial-skipper/935638/13 "2026-03-12T23:05:57Z")

</div>

Is this fixed, yet? Your company is sending out emails to update.

---

<div class="post-metadata">

**Author:** ![Atomatth](https://sea1.discourse-cdn.com/plex/user_avatar/forums.plex.tv/atomatth/32/314355_2.png) [@Atomatth](https://forums.plex.tv/u/Atomatth)\
**Post date:** [March 13, 2026, 1:46pm UTC](https://forums.plex.tv/t/buffer-overflows-in-plex-commercial-skipper/935638/14 "2026-03-13T13:46:00Z")

</div>

If the issue is related to our commercial skipper can you please do the following;

1. Confirm server [DEBUG logging](https://support.plex.tv/articles/201643703-reporting-issues-with-plex-media-server/#toc-1) is enabled, VERBOSE logging is disabled.  
SAVE if changes.
2. Restart PMS
3. Give it two minutes to start and stabilize
4. Start a recording
5. Let the recording finish
6. Let the commercial skipper finish
7. Download the [server logs](https://support.plex.tv/articles/200250417-plex-media-server-log-files/)
8. Attach the logs so I may see them

If you have any previously recorded videos, depending on your server and/or library settings, you can either manually trigger the commercial skipper by Analyzing the video or readding the video or performing a [Plex Dance](https://forums.plex.tv/t/the-plex-dance/197064). More information about the commercial skipper can be found [here](https://support.plex.tv/articles/115003944134-removing-commercials/).

---

<div class="post-metadata">

**Author:** ![Gloppie](https://avatars.discourse-cdn.com/v4/letter/g/74df32/32.png) [@Gloppie](https://forums.plex.tv/u/Gloppie)\
**Post date:** [March 14, 2026, 8:11pm UTC](https://forums.plex.tv/t/buffer-overflows-in-plex-commercial-skipper/935638/15 "2026-03-14T20:11:56Z")

</div>

you would know if you updated this. It’s not compatible with the newest ffmpeg.

---

<div class="post-metadata">

**Author:** ![Atomatth](https://sea1.discourse-cdn.com/plex/user_avatar/forums.plex.tv/atomatth/32/314355_2.png) [@Atomatth](https://forums.plex.tv/u/Atomatth)\
**Post date:** [March 14, 2026, 11:45pm UTC](https://forums.plex.tv/t/buffer-overflows-in-plex-commercial-skipper/935638/16 "2026-03-14T23:45:36Z")

</div>

Can you please describe what the issue is that you’re seeing?

---

<div class="post-metadata">

**Author:** ![Gloppie](https://avatars.discourse-cdn.com/v4/letter/g/74df32/32.png) [@Gloppie](https://forums.plex.tv/u/Gloppie)\
**Post date:** [March 14, 2026, 11:46pm UTC](https://forums.plex.tv/t/buffer-overflows-in-plex-commercial-skipper/935638/17 "2026-03-14T23:46:37Z")

</div>

When I compile the OSS you stripmined, my compiler fuzzing reveals buffer overflows.

---

<div class="post-metadata">

**Author:** ![Atomatth](https://sea1.discourse-cdn.com/plex/user_avatar/forums.plex.tv/atomatth/32/314355_2.png) [@Atomatth](https://forums.plex.tv/u/Atomatth)\
**Post date:** [March 15, 2026, 4:28am UTC](https://forums.plex.tv/t/buffer-overflows-in-plex-commercial-skipper/935638/18 "2026-03-15T04:28:58Z")

</div>

I’m not sure I understand. What are you compiling and how? There should not be anything to compile. Our server installers can be found [here](https://www.plex.tv/media-server-downloads).

---

<div class="post-metadata">

**Author:** ![Gloppie](https://avatars.discourse-cdn.com/v4/letter/g/74df32/32.png) [@Gloppie](https://forums.plex.tv/u/Gloppie)\
**Post date:** [March 15, 2026, 4:30am UTC](https://forums.plex.tv/t/buffer-overflows-in-plex-commercial-skipper/935638/19 "2026-03-15T04:30:50Z")

</div>

and they contain [https://github.com/erikkaashoek/Comskip](https://github.com/erikkaashoek/Comskip) which is insecure.

---

<div class="post-metadata">

**Author:** ![Atomatth](https://sea1.discourse-cdn.com/plex/user_avatar/forums.plex.tv/atomatth/32/314355_2.png) [@Atomatth](https://forums.plex.tv/u/Atomatth)\
**Post date:** [March 15, 2026, 4:54pm UTC](https://forums.plex.tv/t/buffer-overflows-in-plex-commercial-skipper/935638/20 "2026-03-15T16:54:23Z")

</div>

It’s still not clear what the problem is. There shouldn’t be anything that needs to be compiled. This sounds like something outside the scope of what we can provide support for. If you could provide detailed steps of what it is you’re doing, it would be helpful with determining whether we can or cannot provide support.

---

<div class="post-metadata">

**Author:** ![Gloppie](https://avatars.discourse-cdn.com/v4/letter/g/74df32/32.png) [@Gloppie](https://forums.plex.tv/u/Gloppie)\
**Post date:** [March 15, 2026, 5:21pm UTC](https://forums.plex.tv/t/buffer-overflows-in-plex-commercial-skipper/935638/21 "2026-03-15T17:21:49Z")

</div>

You dont even keep track of your software dependents? What do you think Plex Commercial Skipper is? you dont seriously think you guys wrote it do you?

[Next page](https://forums.plex.tv/t/buffer-overflows-in-plex-commercial-skipper/935638.md?page=2)
