Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.4
CVE-2026-57159: Asterisk/pjproject could crash if remote SDP feature enabled
CVE-2026-57159 · published 1 month ago
Summary
Debian and Canonical builds of Asterisk and the pjproject library can experience memory corruption that may stop the service when a specially crafted remote call description is processed and the remote payload‑type map option is turned on. The problem is fixed in the latest code releases, so update to the newest version or disable the remote payload‑type map feature if you do not need it.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| Debian:14 | debian | asterisk | All versions |
| Ubuntu:Pro:16.04:LTS | canonical | asterisk | All versions |
| Ubuntu:Pro:16.04:LTS | canonical | pjproject | All versions |
| – | pjsip | pjproject | < 673b978aab1fe3ab874247be32c871acc880cbeb |
| – | teluu | pjsip |
<= 2.17 cpe:2.3:a:teluu:pjsip:*:*:*:*:*:*:*:* |
Original advisory text
PJSIP: SDP parser out-of-bounds write in remote payload-type map maintenance
PJSIP is a free and open source multimedia communication library written in C. Prior to commit 673b978, a remote out-of-bounds read and write can occur in the SDP negotiator when the remote payload-type map maintenance feature is enabled. assign_pt_and_update_map() in pjmedia/src/pjmedia/sdp_neg.c uses payload-type numbers taken from a remote SDP offer or answer to index fixed-size internal tables without sufficient bounds validation, so a crafted remote SDP can cause memory access outside those tables. The practical impact is memory corruption and denial of service; code execution is not demonstrated. This path is only reached when PJMEDIA_SDP_NEG_MAINTAIN_REMOTE_PT_MAP is enabled. The default is disabled, so default builds are not affected; the feature is an interoperability option that integrating products may enable. This issue has been patched via commit 673b978.
References
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/57xxx/CVE-2026-57159... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-57159 Vendor Advisory
- https://github.com/pjsip/pjproject/commit/673b978aab1fe3ab874247be32c871acc880cb... Patch
- https://security-tracker.debian.org/tracker/CVE-2026-57159 Vendor Advisory
- https://github.com/pjsip/pjproject/security/advisories/GHSA-rfwg-w9gq-9mw2 Patch Vendor Advisory
- https://ubuntu.com/security/CVE-2026-57159 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-57159 Third Party Advisory
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Severity
8.4
High
Type
CWE-129Improper Validation of Array Index
CWE-787Out-of-bounds Write
Timeline
Published4 Sep 2026
Updated9 Oct 2026
First seen4 Sep 2026
Sources
CVE-2026-57159 · NVD
CVE-2026-57159 · MITRE
DEBIAN-CVE-2026-57159 · OSV
CVE-2026-57159 · OSV
GHSA-rfwg-w9gq-9mw2 · GHSA
UBUNTU-CVE-2026-57159 · OSV
Track software like this
Free during beta