Ghostwire

CVE-2026-41416: PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, there is an integer...

CRITICAL CVSS 9.5

Published: April 24, 2026 | Last Modified: April 24, 2026

Description

PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, there is an integer overflow in media stream buffer size calculation when processing SDP with asymmetric ptime configuration. The overflow may result in an undersized buffer allocation, which can lead to unexpected application termination or memory corruption This vulnerability is fixed in 2.17.

Ghostwire Analysis — What This Means Practically

This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.

Security Coverage (1 articles)

References