OpenSIPS: OOB Read in Multipart Body Boundary Parsing
Published Aug 4, 2026
5.3
MEDIUMCVSS 3.1
EPSS 0.51%
Description
OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions prior to 3.6.6 and 4.0.0-rc1, the find_line_delimiter() function in the multipart body parser performs an out-of-bounds read via strncmp() when searching for MIME boundary delimiters. After finding a -- pattern near the end of the body, the function compares delimiter.len bytes (typically 20-70) starting from a position at or past the logical end of the body buffer, reading past the body boundary. The bug triggers when a SIP message has Content-Type: multipart/mixed with a boundary parameter and its body contains -- within two to three bytes of the body's end without being followed by the actual boundary delimiter. This issue has been fixed in versions 3.6.6 and 4.0.0-rc1.
Affected products
-
- Version >= 3.4.0, < 3.6.6StatusaffectedConstraints-
- Version >= 4.0.0-beta, < 4.0.0-rc1StatusaffectedConstraints-
- Version
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (3)
- https://github.com/OpenSIPS/opensips/commit/4d23613b65579b073784a07a65d3bf52443a4efb x_refsource_MISC
- https://github.com/OpenSIPS/opensips/commit/5f103effaf5f372cccffe0b138f16998eba12668 x_refsource_MISC
- https://github.com/OpenSIPS/opensips/security/advisories/GHSA-chxf-9368-fqcp exploitx_refsource_CONFIRM
| Link | Providers | Tags |
|---|---|---|
| https://github.com/OpenSIPS/opensips/commit/4d23613b65579b073784a07a65d3bf52443a4efb | x_refsource_MISC | |
| https://github.com/OpenSIPS/opensips/commit/5f103effaf5f372cccffe0b138f16998eba12668 | x_refsource_MISC | |
| https://github.com/OpenSIPS/opensips/security/advisories/GHSA-chxf-9368-fqcp | exploitx_refsource_CONFIRM |
Change history (0)
No recorded changes yet.