Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.8

CVE-2026-57162: Asterisk/PJProject can crash on malformed crypto lines

CVE-2026-57162 · published 1 month ago
Summary

The Asterisk and PJProject software that handle encrypted voice calls may overflow a temporary storage area when a SIP invitation includes an unusually large number of crypto attributes. This can cause the program to stop working or, in rare cases, let an attacker take control of the process. Apply the latest software updates from your distribution or vendor to fix the problem.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
Ecosystem VendorProductAffected versions
Debian:14 debian asterisk All versions
– pjsip pjproject < a1b707c0c9b0506faf2a8a438b60f11ffd6a6fd9
Ubuntu:Pro:16.04:LTS canonical asterisk All versions
Ubuntu:Pro:16.04:LTS canonical pjproject All versions
– teluu pjsip <= 2.17
cpe:2.3:a:teluu:pjsip:*:*:*:*:*:*:*:*
Original advisory text
PJSIP: Stack overflow parsing SDP a=crypto attributes
PJSIP is a free and open source multimedia communication library written in C. Prior to commit a1b707c, a stack buffer overflow exists in the SRTP/SDES media transport when processing a=crypto attributes during SDP offer/answer (sdes_encode_sdp() in transport_srtp_sdes.c). This affects applications with SRTP enabled (use_srtp optional or mandatory, using SDES keying). During media negotiation, the crypto attributes from the remote SDP are collected into a fixed-size array without bounding their number; a remote peer that includes an excessive number of a=crypto attributes in a single media description can write past the end of that array on the stack. This is reachable from an incoming SIP INVITE during offer/answer, before application-level authentication. Impact may range from unexpected application termination to control flow hijack/memory corruption. Applications that do not enable SRTP are not affected. This issue has been patched via commit a1b707c.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
8.8 High
Exploitation
<1% chance of attack within 30 days
Type
CWE-121Stack-based Buffer Overflow
Timeline
Published4 Sep 2026
Updated9 Oct 2026
First seen4 Sep 2026
Track software like this
Free during beta