PT-2021-6700 · Pjsip+2 · Pjsip+2

Sauwming

·

Published

2021-07-23

·

Updated

2026-03-24

·

CVE-2021-32686

CVSS v2.0

7.1

High

VectorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions PJSIP versions prior to 2.11.1
Description The issue is related to the SSL socket in PJSIP, a free and open source multimedia communication library. It involves a race condition between callback and destroy due to the accepted socket having no group lock, and the SSL socket parent/listener may get destroyed during handshake. These issues occur intermittently in heavy load TLS connections and cause a crash, resulting in a denial of service.
Recommendations For versions prior to 2.11.1, update to version 2.11.1 to resolve the issue. As a temporary workaround, consider restricting the use of heavy load TLS connections to minimize the risk of exploitation.

Fix

DoS

Race Condition

Weakness Enumeration

Related Identifiers

ALT-PU-2024-15954
ALT-PU-2024-16030
BDU:2022-02055
CVE-2021-32686
DLA-2962-1
DLA-3887-1
DSA-4999-1
GHSA-CV8X-P47P-99WR
MGASA-2021-0559
USN-8122-1

Affected Products

Alt Linux
Pjsip
Ubuntu