Bug 2461631 (CVE-2026-41416) - CVE-2026-41416 pjproject: PJSIP: Memory corruption and denial of service via crafted SDP with asymmetric ptime configuration
Summary: CVE-2026-41416 pjproject: PJSIP: Memory corruption and denial of service via ...
Keywords:
Status: NEW
Alias: CVE-2026-41416
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2463388 2463389 2463390 2463391
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-04-24 19:02 UTC by OSIDB Bzimport
Modified: 2026-04-28 08:29 UTC (History)
0 users

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-04-24 19:02:11 UTC
PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, there is an integer overflow in media stream buffer size calculation when processing SDP with asymmetric ptime configuration. The overflow may result in an undersized buffer allocation, which can lead to unexpected application termination or memory corruption This vulnerability is fixed in 2.17.


Note You need to log in before you can comment on or make changes to this bug.