Back

HIGH

PJSIP: Stack buffer overflow in Opus codec parser

Published Mar 6, 2026

Description

PJSIP is a free and open source multimedia communication library written in C. Prior to version 2.17, there is a stack buffer overflow vulnerability when pjmedia-codec parses an RTP payload contain more frames than the caller-provided frames can hold. This issue has been patched in version 2.17.

Affected products

Remediation

Red Hat statement

IMPORTANT: A stack buffer overflow flaw exists in the PJSIP library's Opus codec parser. This vulnerability occurs when processing specially crafted RTP payloads containing more frames than the allocated buffer can hold, potentially leading to denial of service or arbitrary code execution in applications utilizing PJSIP for Opus codec handling.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Metrics

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Mar 6, 2026
Updated Mar 9, 2026
Reserved Mar 3, 2026
CISA Vulnrichment
Updated Mar 9, 2026
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Mar 6, 2026