CVE-2026-57163
published 2026-09-04CVE-2026-57163: PJSIP is a free and open source multimedia communication library written in C. Prior to commit c4a151a, a stack buffer overflow exists in the GnuTLS TLS…
PriorityP354high8.8CVSS 4.0
AVNACLATNPRNUINVCNVIHVAHSCNSINSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.25%
16.7th percentile
PJSIP is a free and open source multimedia communication library written in C. Prior to commit c4a151a, a stack buffer overflow exists in the GnuTLS TLS backend when parsing the Subject Alternative Name extension of a peer certificate (tls_cert_get_info() in ssl_sock_gtls.c). Only GnuTLS builds are affected (--with-gnutls); OpenSSL and Apple SecureTransport/Network.framework builds are not affected. While extracting certificate information after a TLS handshake, an incorrect buffer-size value can cause an oversized SubjectAltName entry to be written past the end of a fixed-size stack buffer. A network-positioned attacker presenting a crafted certificate — a malicious server to a connecting client, or a malicious client to a server that requests certificates — can trigger this during the TLS handshake, before any SIP-level authentication. Impact may range from unexpected application termination to control flow hijack/memory corruption. This issue has been patched via commit c4a151a.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| pjsip | pjproject | < c4a151af86fadd16d9480b2603eeb2abf4fb4f78 | c4a151af86fadd16d9480b2603eeb2abf4fb4f78 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No advisories linked to this vulnerability.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-57163 asterisk: stack overflow parsing a TLS peer certificate's SubjectAltName in GnuTLS backend [epel-all]
bugzilla·2026-09-09·CVSS 8.8
CVE-2026-57163 [HIGH] CVE-2026-57163 asterisk: stack overflow parsing a TLS peer certificate's SubjectAltName in GnuTLS backend [epel-all]
CVE-2026-57163 asterisk: stack overflow parsing a TLS peer certificate's SubjectAltName in GnuTLS backend [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
PJSIP is a free and open source multimedia communication library written in C. Prior to commit c4a151a, a stack buffer overflow exists in the GnuTLS TLS backend when parsing the Subject Alternative Name extension of a peer certificate (tls_cert_get_info() in ssl_sock_gtls.c). Only GnuTLS builds are affected (--with-gnutls); OpenSSL and Apple SecureTransport/Network.framework builds are not affected. While extracting certificate information after a TLS h
Bugzilla
CVE-2026-57163 pjproject: stack overflow parsing a TLS peer certificate's SubjectAltName in GnuTLS backend [epel-all]
bugzilla·2026-09-09·CVSS 8.8
CVE-2026-57163 [HIGH] CVE-2026-57163 pjproject: stack overflow parsing a TLS peer certificate's SubjectAltName in GnuTLS backend [epel-all]
CVE-2026-57163 pjproject: stack overflow parsing a TLS peer certificate's SubjectAltName in GnuTLS backend [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
PJSIP is a free and open source multimedia communication library written in C. Prior to commit c4a151a, a stack buffer overflow exists in the GnuTLS TLS backend when parsing the Subject Alternative Name extension of a peer certificate (tls_cert_get_info() in ssl_sock_gtls.c). Only GnuTLS builds are affected (--with-gnutls); OpenSSL and Apple SecureTransport/Network.framework builds are not affected. While extracting certificate information after a TLS
Bugzilla
CVE-2026-57163 asterisk: stack overflow parsing a TLS peer certificate's SubjectAltName in GnuTLS backend [fedora-all]
bugzilla·2026-09-09·CVSS 8.8
CVE-2026-57163 [HIGH] CVE-2026-57163 asterisk: stack overflow parsing a TLS peer certificate's SubjectAltName in GnuTLS backend [fedora-all]
CVE-2026-57163 asterisk: stack overflow parsing a TLS peer certificate's SubjectAltName in GnuTLS backend [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
PJSIP is a free and open source multimedia communication library written in C. Prior to commit c4a151a, a stack buffer overflow exists in the GnuTLS TLS backend when parsing the Subject Alternative Name extension of a peer certificate (tls_cert_get_info() in ssl_sock_gtls.c). Only GnuTLS builds are affected (--with-gnutls); OpenSSL and Apple SecureTransport/Network.framework builds are not affected. While extracting certificate information after a TLS
Bugzilla
CVE-2026-57163 pjproject: stack overflow parsing a TLS peer certificate's SubjectAltName in GnuTLS backend [fedora-all]
bugzilla·2026-09-09·CVSS 8.8
CVE-2026-57163 [HIGH] CVE-2026-57163 pjproject: stack overflow parsing a TLS peer certificate's SubjectAltName in GnuTLS backend [fedora-all]
CVE-2026-57163 pjproject: stack overflow parsing a TLS peer certificate's SubjectAltName in GnuTLS backend [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
PJSIP is a free and open source multimedia communication library written in C. Prior to commit c4a151a, a stack buffer overflow exists in the GnuTLS TLS backend when parsing the Subject Alternative Name extension of a peer certificate (tls_cert_get_info() in ssl_sock_gtls.c). Only GnuTLS builds are affected (--with-gnutls); OpenSSL and Apple SecureTransport/Network.framework builds are not affected. While extracting certificate information after a TL
Bugzilla
CVE-2026-57163 pjsip: stack overflow parsing a TLS peer certificate's SubjectAltName in GnuTLS backend
bugzilla·2026-09-04·CVSS 8.8
CVE-2026-57163 [HIGH] CVE-2026-57163 pjsip: stack overflow parsing a TLS peer certificate's SubjectAltName in GnuTLS backend
CVE-2026-57163 pjsip: stack overflow parsing a TLS peer certificate's SubjectAltName in GnuTLS backend
PJSIP is a free and open source multimedia communication library written in C. Prior to commit c4a151a, a stack buffer overflow exists in the GnuTLS TLS backend when parsing the Subject Alternative Name extension of a peer certificate (tls_cert_get_info() in ssl_sock_gtls.c). Only GnuTLS builds are affected (--with-gnutls); OpenSSL and Apple SecureTransport/Network.framework builds are not affected. While extracting certificate information after a TLS handshake, an incorrect buffer-size value can cause an oversized SubjectAltName entry to be written past the end of a fixed-size stack buffer. A network-positioned attacker presenting a crafted certificate — a malicious server to a connecti
2026-09-04
Published