CVE-2026-57162
published 2026-09-04CVE-2026-57162: PJSIP is a free and open source multimedia communication library written in C. Prior to commit a1b707c, a stack buffer overflow exists in the SRTP/SDES media…
PriorityP357high8.8CVSS 4.0
AVNACLATNPRNUINVCNVIHVAHSCNSINSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.35%
28.5th percentile
PJSIP is a free and open source multimedia communication library written in C. Prior to commit a1b707c, a stack buffer overflow exists in the SRTP/SDES media transport when processing a=crypto attributes during SDP offer/answer (sdes_encode_sdp() in transport_srtp_sdes.c). This affects applications with SRTP enabled (use_srtp optional or mandatory, using SDES keying). During media negotiation, the crypto attributes from the remote SDP are collected into a fixed-size array without bounding their number; a remote peer that includes an excessive number of a=crypto attributes in a single media description can write past the end of that array on the stack. This is reachable from an incoming SIP INVITE during offer/answer, before application-level authentication. Impact may range from unexpected application termination to control flow hijack/memory corruption. Applications that do not enable SRTP are not affected. This issue has been patched via commit a1b707c.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| pjsip | pjproject | < a1b707c0c9b0506faf2a8a438b60f11ffd6a6fd9 | a1b707c0c9b0506faf2a8a438b60f11ffd6a6fd9 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No advisories linked to this vulnerability.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-57162 pjproject: stack overflow parsing SDP a=crypto attributes [fedora-all]
bugzilla·2026-09-09·CVSS 8.8
CVE-2026-57162 [HIGH] CVE-2026-57162 pjproject: stack overflow parsing SDP a=crypto attributes [fedora-all]
CVE-2026-57162 pjproject: stack overflow parsing SDP a=crypto attributes [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
PJSIP is a free and open source multimedia communication library written in C. Prior to commit a1b707c, a stack buffer overflow exists in the SRTP/SDES media transport when processing a=crypto attributes during SDP offer/answer (sdes_encode_sdp() in transport_srtp_sdes.c). This affects applications with SRTP enabled (use_srtp optional or mandatory, using SDES keying). During media negotiation, the crypto attributes from the remote SDP are collected into a fixed-size array without bou
Bugzilla
CVE-2026-57162 asterisk: stack overflow parsing SDP a=crypto attributes [epel-all]
bugzilla·2026-09-09·CVSS 8.8
CVE-2026-57162 [HIGH] CVE-2026-57162 asterisk: stack overflow parsing SDP a=crypto attributes [epel-all]
CVE-2026-57162 asterisk: stack overflow parsing SDP a=crypto attributes [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
PJSIP is a free and open source multimedia communication library written in C. Prior to commit a1b707c, a stack buffer overflow exists in the SRTP/SDES media transport when processing a=crypto attributes during SDP offer/answer (sdes_encode_sdp() in transport_srtp_sdes.c). This affects applications with SRTP enabled (use_srtp optional or mandatory, using SDES keying). During media negotiation, the crypto attributes from the remote SDP are collected into a fixed-size array without boundi
Bugzilla
CVE-2026-57162 pjproject: stack overflow parsing SDP a=crypto attributes [epel-all]
bugzilla·2026-09-09·CVSS 8.8
CVE-2026-57162 [HIGH] CVE-2026-57162 pjproject: stack overflow parsing SDP a=crypto attributes [epel-all]
CVE-2026-57162 pjproject: stack overflow parsing SDP a=crypto attributes [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
PJSIP is a free and open source multimedia communication library written in C. Prior to commit a1b707c, a stack buffer overflow exists in the SRTP/SDES media transport when processing a=crypto attributes during SDP offer/answer (sdes_encode_sdp() in transport_srtp_sdes.c). This affects applications with SRTP enabled (use_srtp optional or mandatory, using SDES keying). During media negotiation, the crypto attributes from the remote SDP are collected into a fixed-size array without bound
Bugzilla
CVE-2026-57162 asterisk: stack overflow parsing SDP a=crypto attributes [fedora-all]
bugzilla·2026-09-09·CVSS 8.8
CVE-2026-57162 [HIGH] CVE-2026-57162 asterisk: stack overflow parsing SDP a=crypto attributes [fedora-all]
CVE-2026-57162 asterisk: stack overflow parsing SDP a=crypto attributes [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
PJSIP is a free and open source multimedia communication library written in C. Prior to commit a1b707c, a stack buffer overflow exists in the SRTP/SDES media transport when processing a=crypto attributes during SDP offer/answer (sdes_encode_sdp() in transport_srtp_sdes.c). This affects applications with SRTP enabled (use_srtp optional or mandatory, using SDES keying). During media negotiation, the crypto attributes from the remote SDP are collected into a fixed-size array without boun
Bugzilla
CVE-2026-57162 pjsip: stack overflow parsing SDP a=crypto attributes
bugzilla·2026-09-04·CVSS 8.8
CVE-2026-57162 [HIGH] CVE-2026-57162 pjsip: stack overflow parsing SDP a=crypto attributes
CVE-2026-57162 pjsip: stack overflow parsing SDP a=crypto attributes
PJSIP is a free and open source multimedia communication library written in C. Prior to commit a1b707c, a stack buffer overflow exists in the SRTP/SDES media transport when processing a=crypto attributes during SDP offer/answer (sdes_encode_sdp() in transport_srtp_sdes.c). This affects applications with SRTP enabled (use_srtp optional or mandatory, using SDES keying). During media negotiation, the crypto attributes from the remote SDP are collected into a fixed-size array without bounding their number; a remote peer that includes an excessive number of a=crypto attributes in a single media description can write past the end of that array on the stack. This is reachable from an incoming SIP INVITE during offer/answer, bef
2026-09-04
Published