PT-2026-29286 · Debian+3 · Asterisk+2

Sauwming

·

Published

2026-03-31

·

Updated

2026-04-04

·

CVE-2026-34235

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions PJSIP versions prior to 2.17
Description A heap out-of-bounds read exists in the VP9 RTP unpacketizer when parsing crafted VP9 Scalability Structure (SS) data. This occurs due to insufficient bounds checking on the payload descriptor length, which may lead to reads beyond the allocated RTP payload buffer.
Recommendations Update to version 2.17. As a temporary workaround, disable the VP9 codec if it is not required.

Fix

Out of bounds Read

Weakness Enumeration

Related Identifiers

CVE-2026-34235

Affected Products

Asterisk
Pjproject
Pjsip