Unrated severityNVD Advisory· Published Mar 6, 2026· Updated Mar 9, 2026
PJSIP: Stack buffer overflow in Opus codec parser
CVE-2026-29068
Description
PJSIP is a free and open source multimedia communication library written in C. Prior to version 2.17, there is a stack buffer overflow vulnerability when pjmedia-codec parses an RTP payload contain more frames than the caller-provided frames can hold. This issue has been patched in version 2.17.
Affected products
2- pjsip/pjprojectv5Range: < 2.17
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- github.com/pjsip/pjproject/commit/6c9024511bf5307ff72efde1f90c9a2a226d8967mitrex_refsource_MISC
- github.com/pjsip/pjproject/security/advisories/GHSA-pqww-jrxr-457fmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.