Unrated severityNVD Advisory· Published Mar 20, 2026· Updated Mar 20, 2026
PJSIP has ICE session use-after-free race conditions
CVE-2026-32942
Description
PJSIP is a free and open source multimedia communication library written in C. Versions 2.16 and below contain a heap use-after-free vulnerability in the ICE session that occurs when there are race conditions between session destruction and the callbacks. This issue has been fixed in version 2.17.
Affected products
2- pjsip/pjprojectv5Range: < 2.17
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- github.com/pjsip/pjproject/commit/c9caceddabda7f18337b2a82d25d65f6224b450amitrex_refsource_MISC
- github.com/pjsip/pjproject/issues/1451mitrex_refsource_MISC
- github.com/pjsip/pjproject/security/advisories/GHSA-g88q-c2hm-q7p7mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.