CVE-2026-41416

PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, there is an integer overflow in media stream buffer size calculation when processing SDP with asymmetric ptime configuration. The overflow may result in an undersized buffer allocation, which can lead to unexpected application termination or memory corruption This vulnerability is fixed in 2.17.
Configurations

Configuration 1 (hide)

cpe:2.3:a:teluu:pjsip:*:*:*:*:*:*:*:*

History

28 Apr 2026, 18:30

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
References () https://github.com/pjsip/pjproject/commit/66fe416c96e957417621b7be16e9e587d159f9bb - () https://github.com/pjsip/pjproject/commit/66fe416c96e957417621b7be16e9e587d159f9bb - Patch
References () https://github.com/pjsip/pjproject/security/advisories/GHSA-f33g-8hjq-62xr - () https://github.com/pjsip/pjproject/security/advisories/GHSA-f33g-8hjq-62xr - Patch, Vendor Advisory
First Time Teluu pjsip
Teluu
CPE cpe:2.3:a:teluu:pjsip:*:*:*:*:*:*:*:*

24 Apr 2026, 19:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-24 19:17

Updated : 2026-04-28 18:30


NVD link : CVE-2026-41416

Mitre link : CVE-2026-41416

CVE.ORG link : CVE-2026-41416


JSON object : View

Products Affected

teluu

  • pjsip
CWE
CWE-190

Integer Overflow or Wraparound