Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.8
CVE-2026-57163: PJSIP GnuTLS builds can crash from crafted certificate
CVE-2026-57163 · published 1 month ago
Summary
Asterisk and other software that use the PJSIP library with the GnuTLS security component could stop working or be compromised if they receive a specially crafted certificate during a secure connection. The problem occurs because the program writes data beyond a small temporary memory area when it reads the certificate's alternate names. Update to the latest version of the PJSIP library or rebuild the software using OpenSSL or another supported security backend to fix the issue.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| Debian:14 | debian | asterisk | All versions |
| – | pjsip | pjproject | < c4a151af86fadd16d9480b2603eeb2abf4fb4f78 |
| Ubuntu:Pro:16.04:LTS | canonical | asterisk | All versions |
| Ubuntu:Pro:16.04:LTS | canonical | pjproject | All versions |
| – | teluu | pjsip |
<= 2.17 cpe:2.3:a:teluu:pjsip:*:*:*:*:*:*:*:* |
Original advisory text
PJSIP: Stack overflow parsing a TLS peer certificate's SubjectAltName in GnuTLS backend
PJSIP is a free and open source multimedia communication library written in C. Prior to commit c4a151a, a stack buffer overflow exists in the GnuTLS TLS backend when parsing the Subject Alternative Name extension of a peer certificate (tls_cert_get_info() in ssl_sock_gtls.c). Only GnuTLS builds are affected (--with-gnutls); OpenSSL and Apple SecureTransport/Network.framework builds are not affected. While extracting certificate information after a TLS handshake, an incorrect buffer-size value can cause an oversized SubjectAltName entry to be written past the end of a fixed-size stack buffer. A network-positioned attacker presenting a crafted certificate — a malicious server to a connecting client, or a malicious client to a server that requests certificates — can trigger this during the TLS handshake, before any SIP-level authentication. Impact may range from unexpected application termination to control flow hijack/memory corruption. This issue has been patched via commit c4a151a.
References
- https://github.com/pjsip/pjproject/commit/c4a151af86fadd16d9480b2603eeb2abf4fb4f... Patch
- https://security-tracker.debian.org/tracker/CVE-2026-57163 Vendor Advisory
- https://ubuntu.com/security/CVE-2026-57163 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-57163 Third Party Advisory
- https://github.com/pjsip/pjproject/security/advisories/GHSA-jm2j-6rg6-qvwx Patch Vendor Advisory
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/57xxx/CVE-2026-57163... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-57163 Vendor Advisory
Internet-facing
14 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker partial control
Severity
8.8
High
Type
CWE-121Stack-based Buffer Overflow
Timeline
Published4 Sep 2026
Updated9 Oct 2026
First seen4 Sep 2026
Sources
CVE-2026-57163 · NVD
CVE-2026-57163 · MITRE
DEBIAN-CVE-2026-57163 · OSV
CVE-2026-57163 · OSV
GHSA-jm2j-6rg6-qvwx · GHSA
UBUNTU-CVE-2026-57163 · OSV
Track software like this
Free during beta