PT-2026-20971 · Pjsip · Pjsip

Arthurscchan

·

Published

2026-02-20

·

Updated

2026-02-20

·

CVE-2026-26967

CVSS v4.0

8.1

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U
Name of the Vulnerable Software and Affected Versions PJSIP versions 2.16 and below
Description PJSIP, a multimedia communication library written in C, contains a Heap-based Buffer Overflow vulnerability in its H.264 unpacketizer. The issue arises when processing malformed SRTP packets, where the unpacketizer reads a 2-byte NAL unit size field without verifying that both bytes are within the payload buffer boundaries. This affects applications receiving video using H.264. The vulnerability allows remote attackers to potentially crash applications or execute code without authentication.
Recommendations Upgrade to version 2.17 or later.

Exploit

Fix

Heap Based Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2026-26967
GHSA-X2HC-6969-G8V6

Affected Products

Pjsip