216.73.217.22

CVE-2026-41416

· Published 24/04/2026 19:17 · Modified 24/04/2026 19:17

Labels: CVE-2026-41416 2026-04-24CVE-2026-41416CWE-190[email protected]

Essential information

Published
24/04/2026 19:17
Modified
24/04/2026 19:17
Author
Creator
CVSS
8.1 HIGH (v3) 8.1 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, there is an integer overflow in media stream buffer size calculation when processing SDP with asymmetric ptime configuration. The overflow may result in an undersized buffer allocation, which can lead to unexpected application termination or memory corruption This vulnerability is fixed in 2.17.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
pjsip / pjsip cpe:2.3:a:pjsip:pjsip:2.16:*:*:*:*:*:*:*
pjsip / pjsip cpe:2.3:a:pjsip:pjsip:<2.17:*:*:*:*:*:*:*

References