PT-2021-6700 · Pjsip+2 · Pjsip+2

·

CVE-2021-32686

·

Published

2021-07-23

·

Updated

2026-03-24

CVSS v2.0

7.1

High

VectorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions PJSIP versions prior to 2.11.1
Description The issue is related to the SSL socket in PJSIP, a free and open source multimedia communication library. It involves a race condition between callback and destroy due to the accepted socket having no group lock, and the SSL socket parent/listener may get destroyed during handshake. These issues occur intermittently in heavy load TLS connections and cause a crash, resulting in a denial of service.
Recommendations For versions prior to 2.11.1, update to version 2.11.1 to resolve the issue. As a temporary workaround, consider restricting the use of heavy load TLS connections to minimize the risk of exploitation.

Fix

DoS

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2024-15954
ALT-PU-2024-16030
BDU:2022-02055
CVE-2021-32686
DLA-2962-1
DLA-3887-1
DSA-4999-1
GHSA-CV8X-P47P-99WR
MGASA-2021-0559
USN-8122-1

Affected Products

Alt Linux
Pjsip
Ubuntu