Bug 2538360 (CVE-2026-77396) - CVE-2026-77396 pjproject: PJSIP: Memory corruption via crafted AVI file
Summary: CVE-2026-77396 pjproject: PJSIP: Memory corruption via crafted AVI file
Keywords:
Status: NEW
Alias: CVE-2026-77396
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2539359 2539360 2539357 2539358
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-22 18:17 UTC by OSIDB Bzimport
Modified: 2026-09-23 11:36 UTC (History)
0 users

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-22 18:17:12 UTC
PJSIP is a free and open source multimedia communication library written in C. In 2.17 and earlier, the PJSIP AVI parser in pjmedia/src/pjmedia/avi_player.c uses an input-file video chunk length as the number of bytes copied into a frame buffer whose capacity is derived from the declared media dimensions. A crafted AVI file can therefore cause an attacker-controlled out-of-bounds write past the heap allocation when an application plays the file or pulls its frames. The existing size assertion does not protect production release builds, where assertions are disabled. Typical local playback can crash the process, while applications that accept untrusted AVI sources expose a stronger memory-corruption condition. No fixed version is available as of this review.


Note You need to log in before you can comment on or make changes to this bug.